BusinessDrinksEntertainmentFashion

North Korean Hackers Are Targeting Top Crypto Firms With Malware Hidden in Job Applications

North Korean hackers, specifically the Famous Chollima group, are employing a sophisticated phishing campaign targeting cryptocurrency professionals. This campaign utilizes a new Python-based malware, PylangGhost, disguised as a legitimate job application process. The malware, a variant of the previously known GolangGhost RAT, is designed to infect Windows systems, while a Golang version continues to target Mac users. Linux systems remain unaffected.

The attack begins with deceptively realistic job postings mimicking reputable cryptocurrency firms like Coinbase, Robinhood, and Uniswap. Applicants are lured into completing seemingly innocuous skill tests. Upon submission, victims are instructed to execute a command via their terminal, installing what appears to be a video driver. This command secretly downloads and executes the PylangGhost RAT, concealed within a ZIP archive.

The archive contains a renamed Python interpreter (nvidia.py), a Visual Basic script for unpacking, and six core modules. These modules grant the attacker extensive control over the compromised machine. Capabilities include persistence, system information gathering, file transfer, remote shell access, and theft of sensitive data.

PylangGhost’s payload focuses on acquiring login credentials, session cookies, and wallet data from over 80 browser extensions, including popular crypto wallets like MetaMask, Phantom, and TronLink, as well as password managers like 1Password. The malware establishes communication using RC4-encrypted HTTP packets, an outdated encryption method vulnerable to modern decryption techniques.

The similarities between PylangGhost and GolangGhost strongly suggest a common origin, reinforcing the attribution to the DPRK-aligned Famous Chollima group. Victims primarily appear to be located in India, and the campaign’s goal extends beyond individual targets, aiming to infiltrate the companies these individuals might join. This highlights the expanding sophistication and persistent threat posed by state-sponsored cyberattacks within the cryptocurrency industry.

Leave a Reply

Your email address will not be published. Required fields are marked *