A sophisticated malware campaign is actively targeting professionals in the cryptocurrency and Web3 sectors by masquerading as legitimate job recruitment processes. This operation introduces GolangGhost, a remote access trojan (RAT) designed to infiltrate macOS systems, exfiltrate browser credentials, harvest cryptocurrency wallet data, and grant attackers control over compromised devices.
Deceptive Recruitment Tactics
The attackers initiate contact by posing as recruiters offering enticing job opportunities. They direct potential victims to fraudulent online skill assessments. During the final stage of this assessment, a fabricated camera error message appears, prompting users to execute a command in their Mac Terminal to supposedly resolve the issue. This command initiates the installation of the GolangGhost malware.
Security researchers have linked this campaign to the North Korean-affiliated group known as Famous Chollima, also referred to as Wagemole. The operation employs PylangGhost for Windows users and GolangGhost for macOS users, both delivered through the same deceptive recruitment strategy.
Technical Execution of GolangGhost
Upon execution, the provided command triggers a Bash script that creates a concealed working directory, downloads a counterfeit Intel driver archive, and retrieves the Go compiler necessary to run GolangGhost. The script also establishes persistence by creating a Launch Agent, ensuring the malware remains active even after system reboots.
GolangGhost exploits the macOS Keychain command-line utility to extract Chrome’s stored master password. With this information, it decrypts Chrome’s local database, exposing saved browser credentials and cookies. This access can potentially grant attackers entry to various online services associated with the victim.
Furthermore, the malware searches for data related to browser extensions associated with cryptocurrency wallets and password managers, including MetaMask. By collecting extension settings and related data from Chrome profiles, attackers can gain insights into the victim’s digital assets.
Alarmingly, GolangGhost can modify Chrome’s Secure Preferences file after forcibly closing the browser. It injects extensive permissions—such as access to active tabs, clipboard writing, web requests, and expanded storage—and assigns them to the MetaMask extension. This manipulation allows attackers to exploit the wallet extension’s trusted position within the browser.
Broader Implications
The ramifications of this campaign extend beyond individual device compromise. Professionals in the cryptocurrency, investment, legal, advisory, and business sectors often have direct access to wallets, company accounts, or sensitive information. Attackers can leverage this access to misappropriate digital assets or infiltrate deeper into organizational networks.
Similar fake recruiter malware campaigns have persistently targeted the cryptocurrency sector, underscoring the need for heightened vigilance. The ClickFake interview pages employed in this campaign are meticulously designed to prompt swift action from victims. They collect personal information, fingerprint the visitor’s browser and device, block mobile users, present timed assessment questions, and issue warnings when candidates switch browser tabs.
At the final stage, the attackers present a convincing camera or microphone troubleshooting prompt, further deceiving victims into executing malicious commands.
This incident highlights the evolving sophistication of social engineering attacks targeting the cryptocurrency industry. Professionals must exercise caution when engaging with unsolicited recruitment offers and remain vigilant against tactics designed to exploit trust and urgency. Organizations should implement robust security protocols and provide comprehensive training to employees to recognize and mitigate such threats.