Friday, September 11, 2026

North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs

North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview.

The operation targets cryptocurrency and Web3 professionals, tricking candidates into executing terminal commands that infect their devices with platform-specific Remote Access Trojans (RATs): PylangGhost on Windows and GolangGhost on macOS.

Detailed analysis by the SOCRadar Threat Research Unit highlights how the threat actor has industrialized fake recruitment workflows to establish initial access for financial theft and espionage.

North Korean Hackers Use Fake Job Interviews

The attack initiates on social media platforms like LinkedIn and X, where operators pose as recruiters representing well-known Web3 firms such as Coinbase, Robinhood, Uniswap, and Archblock.

After engaging candidates, the fake recruiters direct them to complete a staged “skills assessment” on a fraudulent web portal.

ClickFake Interview attack chain
ClickFake Interview attack chain (Image Source: socradar.io)

Upon completing the test, targets are invited to a video interview on a spoofed meeting platform styled after legitimate hiring software like Willo. During the call, candidates are prompted to authorize camera and microphone permissions.

When the platform simulates a device failure, the candidate is instructed to run a terminal command to “update camera drivers” leveraging the well-known ClickFix social engineering vector. This tactic reflects broader ClickFix threat trends expanding across corporate endpoints.

Executing the terminal command triggers a platform-tailored infection:

  • PylangGhost (Windows): A Python-based RAT compiled into native libraries to evade signature detection.
  • GolangGhost (macOS): A Go-based backdoor sharing functional parity with PylangGhost for remote access, persistence, and file management.
Resource hacker usage for config.pyd
Resource hacker usage for config.pyd (Image Source: socradar.io)

Both RATs systematically harvest credentials, credential stores, and session cookies from over 80 popular browser extensions. High-value targets include password managers like 1Password and NordPass alongside crypto wallets like MetaMask and Phantom.

According to SOCRadar Threat Research, On macOS endpoints, the backdoor may deploy an auxiliary SwiftUI credential harvester to capture system login credentials. Earlier campaign waves also integrated an intermediate module called FROSTYFERRET to assist in live credential capture.

The ClickFake Interview operation represents a direct evolution of the long-running Contagious Interview campaign (also tracked as DeceptiveDevelopment or DEV#POPPER), attributed to North Korea’s Reconnaissance General Bureau under the Lazarus Group umbrella.

Financially motivated DPRK campaigns
Financially motivated DPRK campaigns (Image Source: socradar.io)
Operational ComponentImplementation StrategyTarget Impact
Recruitment PretextSpoofed LinkedIn profiles & fake job portalsBuilds high trust with Web3 talent
Interview LureGenerative AI video filters & stolen identitiesObscures attacker identity in real-time calls
Payload DeliveryClickFix terminal command executionBypasses traditional browser download security
Target Extension Scope80+ extensions (1Password, MetaMask, Phantom)Exfiltrates crypto keys & session tokens

Recent telemetry indicates that over 230 tech professionals were targeted in fake job interview attacks during recent months alone.

Operators have increasingly adopted AI-generated video filters and stolen candidate identities to pass live video screenings, aligning with broader Lazarus macOS targets across the fintech landscape.

To neutralize recruitment-themed social engineering tactics, organizations and job seekers should enforce strict operational safeguards:

  • Reject Terminal Instructions: Treat any requirement to execute terminal commands during a hiring assessment as an immediate security breach attempt.
  • Restrict Endpoint Scripting: Enforce strict script execution and execution-policy controls on endpoints used by recruiters, developers, and HR staff.
  • Vet Browser Extensions: Implement centralized extension whitelisting to limit credential theft from browser memory and local session stores.
  • Monitor Endpoint Indicators: Configure EDR solutions to alert on unexpected process execution originating from terminal shells following web browser sessions.

𝗔𝗜 𝗦𝗢𝗖 𝘃𝘀 𝗠𝗗𝗥 𝘃𝘀 𝗠𝗦𝗦𝗣 Which is Best in 2026? Compare costs, Automation, and response: Download Free Guide

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News