Crypto Jobs in Danger: North Korean Hackers Strike Again With New Malware

Source Bitcoinist

According to Cisco Talos, a North Korean‑aligned group has quietly stepped up efforts to target crypto job hunters in India with a new Python‑based remote access trojan.

The campaign uses fake job sites and staged interviews to trick candidates into running malicious code. Victims end up handing over keys to their wallets and password managers.

Bogus Job Platforms

Job seekers are lured by postings that mimic big names like Coinbase, Robinhood and Uniswap. Recruiters reach out through LinkedIn or email. They invite candidates to a “skill‑testing” site. It feels harmless at first. Behind the scenes, the site is collecting system details and browser info.

Deceptive Interview Process

After the test, candidates join a live video interview. They’re told to update their camera drivers. In a quick move, they copy and paste commands into a terminal window. One click and PylangGhost is installed. The whole scheme runs smoothly—until the malware takes over.

Advanced RAT Tool

PylangGhost is a spin on the earlier GolangGhost tool. Once active, it grabs cookies and passwords from more than 80 browser extensions. This list includes MetaMask, 1Password, NordPass, Phantom, Bitski, Initia, TronLink and MultiverseX.

The trojan then opens a back door for remote control. It can take screenshots, manage files, steal browser data and keep a hidden presence on the system.

History Of Similar Attacks

North Korean hackers used a fake recruitment test in April before the $1.4 billion Bybit heist. And they’ve tried similar tricks with infected PDFs and malicious links.

This group—known as Famous Chollima or Wagemole—has stolen millions through crypto wallet breaches since 2019. Their goal is simple: get valid credentials and then quietly move funds.

Industry Response Measures

Security teams are on alert. They recommend checking every URL for spelling mistakes and odd domains. Experts say to verify job offers through trusted channels.

Endpoint detection tools should flag any script that calls remote servers. And multi‑factor authentication can block stolen passwords from giving full access.

This alert shows how far state‑linked actors will go to steal crypto assets. The mix of social engineering and custom malware is a potent risk. Anyone hunting for work in blockchain should double‑check every link and never run unverified code.

Keeping hardware wallets offline and using separate profiles for job hunting can cut down on exposure. Vigilance in the hiring process and solid technical controls remain the best defense against these evolving threats.

Featured image from Shutterstock, chart from TradingView

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Solana Plunges 13%: Can Key On-Chain Support Stop The Fall?Solana has declined by around 13% in the past week, which has brought the asset back to a major on-chain support cluster. Could this be where the bleed ends? Solana Has Strong On-Chain Support
Author  NewsBTC
Yesterday 09: 56
Solana has declined by around 13% in the past week, which has brought the asset back to a major on-chain support cluster. Could this be where the bleed ends? Solana Has Strong On-Chain Support
placeholder
EUR/USD extends losses as geopolitical tensions sour market sentimentThe EUR/USD pair is extending its reversal from last week's highs on Thursday, weighed by investors' aversion to risk, as fears of an escalation of the Israel-Iran war into a regional conflict have overshadowed the Federal Reserve's (Fed) monetary policy decision.
Author  FXStreet
Yesterday 09: 55
The EUR/USD pair is extending its reversal from last week's highs on Thursday, weighed by investors' aversion to risk, as fears of an escalation of the Israel-Iran war into a regional conflict have overshadowed the Federal Reserve's (Fed) monetary policy decision.
placeholder
US Dollar Index (DXY) crawls beyond 98.00 supported by risk aversionThe Dollar has recovered its safe-haven status amid fears that the Middle East conflict escalates into a regional war with the US intervention.
Author  FXStreet
Yesterday 09: 54
The Dollar has recovered its safe-haven status amid fears that the Middle East conflict escalates into a regional war with the US intervention.
placeholder
XRP-focused DeFi services expand with cbXRP support on Base, Flare networks’ staking model The role of Ripple’s XRP token is expanding the broader Decentralized Finance (DeFi) market with the extended support of multiple platforms. Flare’s constant effort to boost XRP DeFi (XRPFi) attracted $100 million from Vivo Power, an electric vehicle services company. 
Author  FXStreet
Yesterday 09: 53
The role of Ripple’s XRP token is expanding the broader Decentralized Finance (DeFi) market with the extended support of multiple platforms. Flare’s constant effort to boost XRP DeFi (XRPFi) attracted $100 million from Vivo Power, an electric vehicle services company. 
placeholder
SUI Preparing For New Highs As Falling Wedge Breakout Targets $5After falling below the key $3.00 mark, SUI now retests a make-or-break level that could ignite or stall the cryptocurrency’s rally. However, some market watchers believe that the altcoin is
Author  NewsBTC
Yesterday 09: 52
After falling below the key $3.00 mark, SUI now retests a make-or-break level that could ignite or stall the cryptocurrency’s rally. However, some market watchers believe that the altcoin is
goTop
quote