VYPR
researchPublished Jul 21, 2026· 1 source

North Korean 'ClickFake' Campaign Targets Web3 Professionals with Sophisticated Job Scams

North Korean state-sponsored hackers are employing elaborate social engineering tactics, posing as recruiters to deliver custom malware to Web3 professionals through fake job assessment portals.

Researchers at SOCRadar have uncovered a sophisticated social engineering operation, dubbed 'ClickFake,' orchestrated by the North Korean state-aligned hacking group Famous Chollima, also known as Wagemole. This campaign specifically targets professionals within the Web3 and cryptocurrency sectors, utilizing personalized recruitment scams to deliver remote access trojans (RATs) for both Windows and macOS.

The threat actors are moving away from broad phishing campaigns, instead opting for highly individualized approaches that exploit the transient nature of talent in the cryptocurrency market. Famous Chollima crafts elaborate pretexts, often posing as recruiters from legitimate firms or establishing entirely fictitious companies, to build trust with potential victims. They entice developers and administrators with lucrative job offers and career advancement opportunities, guiding them towards a mandatory skill assessment.

Once a candidate agrees to the assessment, they are directed to a meticulously crafted online platform controlled by the attackers. These malicious web interfaces are designed to appear authentic, featuring real-time monitoring, psychometric analysis, strict gating mechanisms, tailored interview questions, and countdown timers to create psychological pressure. The platform even includes features that deter users from switching browser tabs, preventing them from researching the suspicious environment.

The core of the deception, termed 'ClickFix,' involves simulating a system error that claims the platform cannot access the user's camera or microphone. To resolve this fabricated issue, the candidate is prompted to execute a diagnostic command in their system terminal. This social engineering tactic leverages the target's desire to perform well under pressure, bypassing typical security warnings.

For Windows users, executing the command triggers a complex infection chain. Native system utilities like PowerShell are used to download a compressed archive containing a Python runtime and an execution wrapper. This ultimately deploys PylangGhost, a highly customized RAT compiled into native dynamic link libraries using Nuitka to evade signature-based detection.

macOS users face a similar infection process but with a different toolset. The malicious command fetches and executes GolangGhost, a RAT written in Go. On Apple devices, the infection often includes a credential-harvesting helper application built with SwiftUI, designed to trick users into divulging their administrative passwords.

Both PylangGhost and GolangGhost are modular malware suites, comprising six interconnected parts including an orchestrator, configuration holder, archive helper, command launcher, C2 communications module, and a data stealer. The primary goal is financial gain through asset theft, with the stealer module targeting over 80 browser extensions and cryptocurrency wallets like MetaMask, Phantom, and TronLink, as well as password managers such as NordPass.

Famous Chollima prioritizes speed and volume in their operations, rapidly registering domains and deploying new assessment portals as old ones are blacklisted. They employ precise targeting controls, such as blocking mobile devices and validating invitation links, to hinder analysis by security researchers and automated sandboxes. The campaign poses a significant risk not only to individuals but also to organizations, as employees may use company devices for job searching and interviews, potentially granting attackers indirect access to corporate funds.

Synthesized by Vypr AI