North Korean Hackers Use Fake Job Interviews to Infect Windows and Macs
- 1 minute ago
- 1 min read
North Korean hackers are targeting cryptocurrency and Web3 professionals with fake job interviews that install remote access malware on Windows and macOS computers.
Researchers at SOCRadar linked the campaign to Famous Chollima, also known as Wagemole. The group poses as recruiters, impersonates legitimate companies and directs victims to convincing online skills assessments.
The sites collect personal information, present job-specific questions and pressure candidates with countdown timers and warnings when they switch browser tabs. At the final stage, the platform claims the camera or microphone is not working and tells the candidate to paste a command into a terminal to fix it.
That command installs PylangGhost on Windows or GolangGhost on macOS. Mac victims may also receive a SwiftUI-based credential stealer. The malware can execute commands, steal data and communicate with attacker-controlled servers.
The campaign is designed to avoid security analysis. Invitation links are individually validated, mobile users are blocked and attackers can monitor a victim’s progress in real time before triggering the fake camera error.
The operation shows how North Korean cyber groups are shifting from broad phishing campaigns to highly personalized recruitment scams. Cryptocurrency workers should treat any interview process that asks them to open PowerShell, Command Prompt or Terminal as malicious.