North Korean ClickFake Interviews Target Web3 Experts to Steal Crypto Assets
North Korean Target Web3 Experts to Steal Crypto Assets
North Korean hackers are running a smart scam that tricks Web3 and crypto workers into installing dangerous software on their computers. The group uses fake job offers to reach their targets and steal digital money.
What Is the
Researchers found this new trick called the ClickFake campaign. It is run by a North Korean hacking group known as Famous Chollima. Instead of sending random emails, the hackers send personal messages on LinkedIn, Telegram, and Discord. They pretend to be recruiters from big companies and offer high paying jobs in crypto.
Once a person agrees, they are sent to a fake interview website. The site looks real and even shows questions that match the job. It uses timers and warnings to stop people from leaving the page or checking if it is safe.
How the Scam Tricks People
During the fake test, the site says there is a problem with the camera or microphone. It then tells the person to copy and paste a command into their computer terminal to fix it. This command actually downloads malware.
On Windows computers the malware installs a tool called PylangGhost. On Mac computers it installs GolangGhost. Both tools are made to stay hidden and steal information from browsers and crypto wallets.
What the Malware Steals
The malware looks for data from more than 80 browser extensions. It takes passwords, login sessions, and private keys from popular wallets like MetaMask, Phantom, and TronLink. It can also grab details from password managers.
Because many Web3 workers use their own devices for work, one successful attack can lead to the loss of large amounts of crypto. The hackers want money and can also use the access to reach company systems.
Why This Attack Is Hard to Spot
The hackers make new fake websites very fast using cheap domain services. They block phones and check special links so security tools cannot easily study the malware. The code is also changed to avoid normal antivirus detection.
How to Stay Safe
- Never copy and paste commands from unknown websites into your terminal.
- Check every job offer carefully, especially those that seem too good to be true.
- Use strong security tools that watch for unusual activity on your device.
- Do not use work computers for personal job searches.
- Turn on two factor authentication on all crypto accounts and wallets.
Web3 professionals should be extra careful when looking for new jobs. This campaign shows that hackers are getting better at using trust and fake interviews to reach their targets. Staying alert and following basic safety steps can help protect your crypto assets from these attacks.