• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Monday, July 14, 2025
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Crypto

North Korea’s “PylangGhost”: Malware-infected Job Scams Target Crypto Experts

by Anindya Paul
June 21, 2025
in Crypto
Reading Time: 4 mins read
0
PylangGhost

Source: The Jerusalem Post

TwitterWhatsappLinkedin

North Korea’s notorious cyber unit Famous Chollima (a.k.a. Wagemole) is at it again; they are taking advantage of the rise in job opportunities in the blockchain and cryptocurrency spaces, especially in India, by running another round of deceptive recruitment scams against professionals. In short, after publishing fake job postings, increasingly elaborate skill assessments, and fake video interviews, they are installing a powerful remote access trojan (RAT) whereas PylangGhost runs on Python. The goal here: access personal data, browser credentials, crypto wallets and ultimately to compromise legitimate crypto companies.

You might also like

Institutional Bitcoin Boom: Bitwise CIO Predicts BTC Rally to $200,000 by Year-End

Bitcoin Overtakes Google and Silver, Sets Sights on Amazon

CZ Strikes Back: Binance Founder Threatens Bloomberg with Defamation Lawsuit

Luring with Fake Crypto Job Postings

Using professional-looking fake websites that are too good to be true – examples include Coinbase, Robinhood, Uniswap, and Archblock – to luring applicants into completing a “skill assessment.” Recruiters contact victims using professional platforms (LinkedIn) or well-crafted emails. Baiting platforms collect personal and technical details under the false pretenses of normal recruitment.

The Deceptive Video Interview Ruse

After a candidate passes the initial screening, they are invited to the next interviewing phase, which is a video interview. In these interviews applicants are asked to give permissibility to use the camera and microphone, then asked to undertake an act that looks like executing a driver-installation command. What the candidates actually execute is a PylangGhost RAT download that is disguised as “video driver updates.”

What PylangGhost Does

Once deployed on Windows systems, PylangGhost grants persistent remote access, fingerprinting the device and establishing connections to command-and-control (C2) servers. Critically, it extracts credentials and session cookies from over 80 browser extensions—especially crypto wallets (MetaMask, Phantom, TronLink) and password managers (1Password, NordPass). It can also take screenshots, extract browser data, manage files, and run arbitrary remote commands.

A New Variant of an Older Threat

This Python-based Trojan is a direct counterpart to the earlier GolangGhost, which was developed for macOS systems. Research indicates it shares nearly identical structure and naming, pointing to the same developer group behind both RATs. Windows is now the primary target, while Linux systems remain untouched.

Not the First Time—and Not the Last

Famous Chollima has been implicated in multiple prior recruitment-based campaigns, including “Contagious Interview” and “DeceptiveDevelopment” scams targeting developers on platforms like GitHub, Upwork, and CryptoJobsList since at least 2023. They also ran fake U.S.-based companies—BlockNovas LLC and SoftGlide LLC—to distribute malware via sham interviews before the FBI took down the BlockNovas domain.

Wider North Korean Crypto Cybercrime Context

These efforts sit within a broader strategy by DPRK cyber operatives, including the notorious Lazarus Group, to raise funds and gain insider access. A 2024 joint statement from Japan, South Korea, and the U.S. confirmed that North Korean-linked teams stole at least $659 million in crypto assets last year. Notable cases include the $50 million Radiant Capital breach in December 2024—triggered via malicious PDF sent to engineers—and a thwarted infiltration attempt at Kraken, foiled when the applicant failed identity checks.

The Indian Connection and Calls for Defenses

Open-source analysis indicates victims are largely based in India. Dileep Kumar H V, director at Digital South Trust, warned that India should enforce cybersecurity audits for blockchain firms and flag fake recruitment sites. He also urged CERT-In, MEITY, and NCIIPC to issue red alerts and improve cross-border collaboration.

Protecting Against RAT Scams

Security experts recommend several practical steps for safe job hunting in the crypto world:

  • Never run unsolicited download commands during interviews.
  • Verify all job portals via official company channels.
  • Use dedicated devices for job applications, separated from personal crypto wallets.
  • Deploy endpoint protection and monitor unusual outbound connections or ZIP downloads.
  • Enable multi-factor authentication, and maintain strict browser extension hygiene.

Conclusion

The PylangGhost campaign highlights how cybercriminals blend social engineering with custom malware to exploit crypto talent. As North Korean hack groups extend their reach from exchange heists to inside-the-company infiltration, crypto professionals must adopt a cautious posture. Verifying job legitimacy, isolating crypto assets, and building digital security competencies are no longer optional—they are essential protections in an era of sophisticated cyber threats.

Tweet55SendShare15
Previous Post

Reddit Explores Iris-Scanning “Orb” to Verify Users While Preserving Anonymity

Next Post

Healthcare Meets Crypto: David Beckham–Backed Prenetics Launches $20M Bitcoin Treasury

Anindya Paul

Professional content creator with strong expertise in content writing, filmmaking and social media strategy. Skilled in digital storytelling, scriptwriting, video production, sound design and graphic design - crafting compelling narratives across platforms. Known for delivering high-quality, engaging content under tight deadlines. A collaborative team player with a sharp creative instinct, adaptability to evolving trends, and a focus on impactful, results-driven communication.

Recommended For You

Institutional Bitcoin Boom: Bitwise CIO Predicts BTC Rally to $200,000 by Year-End

by Anindya Paul
July 13, 2025
0
Bitcoin

A strong surge of institutional demand for Bitcoin is transforming the cryptocurrency environment. Matt Hougan, Chief Investment Officer at Bitwise Asset Management, believes this influx of demand, paired with...

Read more

Bitcoin Overtakes Google and Silver, Sets Sights on Amazon

by Anindya Paul
July 13, 2025
0
Bitcoin

Once again, Bitcoin has obliterated expectations. In July, during a market rally, the world's largest cryptocurrency reached an all-time high near $118,755, propelling its market capitalization above traditional...

Read more

CZ Strikes Back: Binance Founder Threatens Bloomberg with Defamation Lawsuit

by Anindya Paul
July 13, 2025
0
CZ

Binance’s founder Changpeng “CZ” Zhao has escalated tensions with Bloomberg, publicly threatening legal action over a recent article he labels a “hit piece.” In a fiery response on...

Read more
Next Post
Perentics

Healthcare Meets Crypto: David Beckham–Backed Prenetics Launches $20M Bitcoin Treasury

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at [email protected]

Advertise With Us

Reach out at - [email protected]

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook flipkart funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News NFT samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2024 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2024 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?