Infosecurity-Magazine
North Korean ClickFake Campaign Targets Web3 Professionals with RATs
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researchers at SOCRadar have identified a new social engineering campaign by North Korea's Famous Chollima group, targeting Web3 and cryptocurrency professionals. The operation, dubbed ClickFake, employs fraudulent job interviews to lure candidates into executing malicious terminal commands. Victims are tricked into installing PylangGhost on Windows and GolangGhost on macOS via highly interactive web portals that simulate recruitment processes. The campaign uses platforms like Telegram and Discord to reach targets, offering lucrative job opportunities to entice them. Once engaged, candidates face psychological pressure through countdown timers and warnings against switching tabs. The attackers utilize advanced techniques to evade detection, including compiling their payloads into native dynamic link libraries. This targeted approach signifies a shift from broad phishing tactics to more personalized scams. The current status of the campaign remains active, with ongoing threats to the cryptocurrency sector.
Key Points: • North Korean hackers are targeting Web3 professionals through fake job interviews. • The ClickFake campaign deploys PylangGhost and GolangGhost RATs via malicious terminal commands. • Attackers utilize psychological tactics and advanced evasion techniques to deceive victims.