It is done via fake crypto job interviews, using modular RATs and extensive social engineering.
Who Needs a Job? DPRK ClickFake Interview Campaign Drops PylangGhost and GolangGhost RATs
This article by SOCRadar Threat Research Unit (STRU) analyzes the latest ClickFake Interview campaign, a North Korean social engineering operation that targets cryptocurrency and Web3 professionals with fake job interviews. Operators posing as recruiters walk targets through a bogus skill assessment that ends in a copy-and-paste command, delivering the PylangGhost RAT on Windows and the GolangGhost RAT on macOS.
SOCRadar Threat Research Unit analyze the latest ClickFake Interview campaign, a North Korean social engineering operation that targets cryptocurrency...
socradar.io
North Korea, officially the Democratic People’s Republic of Korea (DPRK), is well known for their financially motivated cyber operations. To circumvent international
sanctions, they persistently attack organizations to steal funds and support the regime’s missile, nuclear, and espionage programs. From historically targeting
SWIFT transactions and
ATMs, they now focus on stealing
crypto assets, with
$643M stolen so far this year.
To accomplish these attacks, since at least early 2023, their cyber operators heavily employ social engineering via fake remote IT workers working on various organizations (“
North Korean IT Worker Scheme”), fake technical interviews (“
Contagious Interview”) and
code supply chain attacks (e.g., the
Polin Rider campaign) to reach developers employed at their targets of interest; and fake non-technical interviews (“
ClickFake Interview“) to reach crypto and Web3 audiences directly.
Financially motivated DPRK campaigns
In this blogpost we analyze their latest iteration of
ClickFake Interview, conducted by
Famous Chollima targeting professionals in the crypto sector via
ClickFix lures, delivering
PylangGhost (for Windows) and
GolangGhost (for macOS) Remote Access Trojans (RATs).
Key Points
- Famous Chollima (aka Wagemole) is a North Korean-aligned threat actor that has been highly active through the Contagious Interview and the latest ClickFake Interview campaigns.
- For ClickFake Interview the actors are creating fraudulent companies or impersonating known ones in the crypto industry, and reach out to targets on social media (e.g., LinkedIn), inviting them to ClickFix empowered fake skill assessments.
- Their ClickFix panels incorporate gating, tailored questions based on advertised roles, psychological pressure to act fast, video recording, and social engineering that pushes targets to run malicious commands through fake camera errors.
- The final payloads target both Windows, by deploying PylangGhost RAT, and macOS, by deploying GolangGhost RAT alongside a credential-harvesting SwiftUI application.
- PylangGhost and GolangGhost consist of six interconnected modules: a main orchestrator, a configuration holder, an archive helper, a command launcher, a C2 component, and a stealer.
- Both payload chains download the runtimes needed to run in victim environments: Python’s interpreter for PylangGhost and Golang’s compiler for GolangGhost.
- In the latest variation of PylangGhost, the attackers also compiled their payloads as Python dynamic modules with Nuitka to further complicate detection and analysis.
- Famous Chollima actors register multiple domains for their fake skill assessments, predominantly on Hostinger and NameCheap registrars, emphasizing speed and scale, rather than operational security and infrastructure resilience.