• CONTACT
  • MARKETCAP
  • BLOG
Crypto NEWS
  • BOOKMARKS
  • Home
  • Shop
  • Bitcoin
  • Crypto News
  • Altcoin
  • Blockchain
  • Market Trends
  • Legal Docs
    • Contact
    • Privacy Policy
    • Terms and Conditions
    • About CryptoNewsUpdate.com
Reading: North Korea Targets Crypto Jobs With New Malware
Share

Crypto NEWS

0
Font ResizerAa
  • Home
  • Shop
  • Bitcoin
  • Crypto News
  • Altcoin
  • Blockchain
  • Market Trends
  • Legal Docs
Search
  • Home
  • Shop
  • Bitcoin
  • Crypto News
  • Altcoin
  • Blockchain
  • Market Trends
  • Legal Docs
    • Contact
    • Privacy Policy
    • Terms and Conditions
    • About CryptoNewsUpdate.com
Have an existing account? Sign In
Follow US
© Crypto NEWS Update. All Rights Reserved.
Crypto NEWS > Blog > Crypto News > North Korea Targets Crypto Jobs With New Malware
Crypto News

North Korea Targets Crypto Jobs With New Malware

yangzeph4@gmail.com
Last updated: June 20, 2025 4:57 am
yangzeph4@gmail.com Published June 20, 2025
Share

A North Korean-aligned threat actor has been targeting job seekers in the crypto industry with new malware that is designed to steal passwords for crypto wallets and password managers.

Cisco Talos reported on Wednesday that it found a new Python-based remote access trojan (RAT) it called “PylangGhost,” linking the malware to a North Korean-affiliated hacking collective called “Famous Chollima,” also known as “Wagemole.”

The hacking group has been targeting job seekers and employees with cryptocurrency and blockchain experience, primarily in India, with the attacks carried out through fake job interview campaigns using social engineering.

“Based on the advertised positions, it is clear that the Famous Chollima is broadly targeting individuals with previous experience in cryptocurrency and blockchain technologies.” 

Fake job sites and tests a cover for malware

The attackers create fraudulent job sites that impersonate legitimate companies, such as Coinbase, Robinhood and Uniswap, and victims are guided through a multi-step process. 

This includes initial contact from fake recruiters who send invites to skill-testing websites where the information gathering occurs.

Sample of fake job website. Source: Cisco Talos

Next, the victims are lured into enabling video and camera access for fake interviews during which they are tricked into copying and executing malicious commands under the pretense of installing updated video drivers, resulting in the compromise of their device. 

Payload targets crypto wallets 

PylangGhost is a variant of the previously documented GolangGhost RAT, and shares similar functionality, Cisco Talos said.

Upon execution, the commands enable remote control of the infected system and the theft of cookies and credentials from over 80 browser extensions, it reported. 

These include password managers and cryptocurrency wallets, including MetaMask, 1Password, NordPass, Phantom, Bitski, Initia, TronLink and MultiverseX. 

Instructions to download the payload. Source: Cisco Talos

Multitasking malware 

The malware can carry out other tasks and execute numerous commands, including taking screenshots, managing files, stealing browser data, collecting system information and maintaining remote access to infected systems.

Related: Scammers use fake crypto jobs, ‘GrassCall’ meeting app to drain wallets

The researchers also noted that it was unlikely that the threat actors used an artificial intelligence large language model to help write the code, based on the comments made within it.

Fake job lures not new 

It is not the first time North Korean-linked hackers have used fake jobs and interviews to lure their victims. 

In April, hackers linked to the $1.4 billion Bybit heist were targeting crypto developers using fake recruitment tests infected with malware. 

Magazine: Arthur Hayes doesn’t care when his Bitcoin predictions are totally wrong

You Might Also Like

Crypto Analyst Predicts $4 Dogecoin After Exhausted Selling Phase

BlackRock ETF buys 3.25% of BTC supply as New Bitcoin Capital dries up

Only 30% Of Crypto Miners Operate Legally In Russia

Analyst Warns Of Bitcoin Breakdown—’If This Continues, It Snaps’

Crypto Crime Supercycle Very Real ZachXBT Says

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article Arizona Senate Revives Bitcoin Reserve Bill
Next Article Apple Considers Generative AI For Custom Chip Design
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow US

Find US on Socials

Subscribe to our newslettern

Get Newest Articles Instantly!

Popular News
Solana Gears Up For Wild Ride: Unpacking SOL USD Price Action In June
Blocktech Brew Join Hands With Qila To Promote Web3 Services Across Industries!
$150M money market funds added to Arbitrum’s RWA ecosystem

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Crypto NEWS

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad image
© Crypto NEWS Update. All Rights Reserved.
Welcome Back!

Sign in to your account

Lost your password?