Famous Chollima Uses Fake Interviews to Deliver Cross-Platform RATs

SOCRadar's Threat Research Unit said on July 20 that North Korean-aligned Famous Chollima is using fake recruiter outreach and skills-assessment portals to trick cryptocurrency and Web3 professionals into running malicious commands. The latest ClickFake Interview chain delivers PylangGhost on Windows and GolangGhost on macOS, giving the actor remote access and targeting browser-held credentials, wallet extensions, and password managers.
SOCRadar's Threat Research Unit reported on July 20 that Famous Chollima, a North Korean-aligned actor also tracked as Wagemole, is using fake recruitment workflows to target cryptocurrency and Web3 professionals. The latest iteration of the campaign, which the researchers call ClickFake Interview, delivers the PylangGhost remote-access trojan on Windows and GolangGhost on macOS.
The report documents an active social-engineering and malware-delivery chain; it does not disclose a victim count or a confirmed financial-loss total for this iteration. Infosecurity Magazine separately reviewed the findings and reported the same campaign mechanics and attribution.
From recruiter message to terminal command
The operators pose as recruiters or create fraudulent companies, contact targets through services such as LinkedIn, Discord, Telegram and email, and direct them to a tailored skills-assessment site. The portal uses role-specific questions, invitation gating and a simulated camera or microphone problem to make the interaction appear credible.
The decisive step is a ClickFix-style instruction that asks the target to copy and run a command presented as a technical remedy. On Windows, SOCRadar says the chain installs PylangGhost through a bundled Python runtime. On macOS, it downloads a Go toolchain and launches GolangGhost alongside a credential-harvesting application.
Cisco Talos documented the same malware family and fake-interview method in June 2025. Its earlier analysis found that PylangGhost and GolangGhost share remote-control and credential-theft capabilities, providing useful lineage for SOCRadar's newly reported variant without establishing that every earlier indicator remains current.
What the malware targets
SOCRadar describes both trojans as modular implants with components for configuration, command execution, archiving, command-and-control traffic and data theft. The researchers say the payloads can collect browser cookies and credentials, including data associated with cryptocurrency wallets and password-manager extensions.
The latest Windows variant is compiled into Python extension modules, while the macOS chain includes persistence through a LaunchAgent and a SwiftUI credential prompt. These are researcher-reported capabilities; LDS has not independently executed the malware.
Defensive relevance
For security teams, the campaign turns an apparently routine hiring step into user-initiated shell execution. Browser-to-terminal telemetry, controls on script and archive execution, managed extension inventories, and phishing-resistant authentication can reduce exposure. Teams handling wallet, exchange or administrative credentials can also require staff to verify recruiter identities and assessment domains through a known company channel before running software or commands.
Key Points
- 1SOCRadar reported on July 20 that Famous Chollima is using tailored fake interviews and ClickFix-style instructions against cryptocurrency and Web3 professionals.
- 2The reported chain delivers PylangGhost on Windows and GolangGhost on macOS, with remote-control and browser-credential theft capabilities.
- 3Cisco Talos' June 2025 research supports the malware lineage and earlier fake-interview method, while SOCRadar provides the primary evidence for the latest variant.
Scoring Rationale
This is a current, technically documented social-engineering campaign against cryptocurrency and Web3 professionals, with cross-platform malware aimed at browser-held credentials and wallet access. It is highly relevant to endpoint and identity defenders but remains narrower than a mass exploitation event or broadly exposed platform vulnerability.
Sources
Primary source and supporting public references used for this report.
View 3 more sources
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

