North Korean Group Famous Chollima Uses Fake Job Interviews to Deploy GolangGhost Malware on macOS
A sophisticated phishing campaign, attributed to North Korea's Famous Chollima group, is targeting cybersecurity and Web3 professionals with the GolangGhost malware via deceptive job interview lures.

A new malware campaign, linked to the North Korean state-sponsored hacking group Famous Chollima (also known as Wagemole), is actively targeting professionals in the cryptocurrency, investment, and legal sectors. The operation employs a deceptive social engineering tactic, using fake job interviews to trick macOS users into downloading and executing the GolangGhost malware. This sophisticated remote access trojan is designed to steal sensitive credentials, compromise cryptocurrency wallets, and ultimately provide attackers with control over infected systems.
The attack chain begins with malicious actors posing as recruiters, offering attractive job opportunities to lure victims. Potential candidates are directed to fake online skill assessment platforms. The final stage of this deceptive process involves a simulated video interview, during which victims are presented with a fabricated camera error message. To 'fix' the issue, they are instructed to copy and paste a command into their Mac's Terminal application. Unbeknownst to the victim, this command initiates the download and execution of the GolangGhost malware.
Once installed, GolangGhost establishes persistence on the macOS system using a Launch Agent, ensuring it remains active even after reboots. A key capability of the malware is its ability to decrypt Chrome's stored master password by leveraging the macOS Keychain utility. With this decrypted password, GolangGhost can access Chrome's local database, exfiltrating saved browser credentials and cookies. This allows attackers to gain unauthorized access to various online services and accounts that users have saved within their browser.
Beyond stealing general browser credentials, GolangGhost specifically targets cryptocurrency wallet extensions and password managers. It searches for and collects data associated with popular wallet extensions like MetaMask, as well as other sensitive information stored within Chrome profiles. The malware's capabilities are further amplified by its ability to modify Chrome's 'Secure Preferences' file. After forcing the browser to close, GolangGhost injects broad permissions into extensions, including access to active tabs, clipboard manipulation, web requests, and expanded storage. This malicious modification could grant attackers significant control over trusted wallet extensions, potentially leading to the hijacking of user accounts and digital assets.
The campaign utilizes a multi-stage approach to maximize its success rate. The fake interview pages are meticulously designed to create a sense of urgency and legitimacy, employing techniques such as collecting personal information, browser fingerprinting, and blocking mobile users. Timed assessment questions and warnings against tab-switching further pressure victims into compliance. The final 'troubleshooting' step is crucial, as it replaces the harmless command displayed to the user with the malicious one, while presenting expected Terminal output to minimize suspicion.
In addition to GolangGhost for macOS, the same deceptive recruitment process is used to deliver a related malware, PylangGhost, to Windows users. This indicates a coordinated effort by the Famous Chollima group to target a broad range of professionals across different operating systems. The financial motivation behind these campaigns is clear, as individuals in the targeted sectors often have direct access to valuable digital assets and sensitive corporate information.
Organizations are urged to implement robust security awareness training for their employees, particularly those in non-technical roles, emphasizing caution towards unsolicited job offers and suspicious 'troubleshooting' instructions. Security teams should also monitor for unexpected Launch Agents, review browser preference changes, and deploy detection mechanisms capable of identifying suspicious compiled modules and dynamic libraries. The threat underscores the importance of avoiding untrusted recruitment software and maintaining vigilance against evolving social engineering tactics.