GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous Chollima / ClickFake Interview) — Threadlinqs Intelligence
As of 2026-07-22, GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous Chollima / ClickFake Interview) is a high-severity malware threat attributed to WageMole (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 42 indicators of compromise.
Threat ID: TL-2026-1610 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: WageMole · North Korea · FINANCIAL
North Korea-aligned Famous Chollima (Wagemole) is running a fake-recruitment 'ClickFake Interview' campaign against cryptocurrency and Web3 professionals, using a staged camera/microphone-fix ClickFix
Famous Chollima (also tracked as Wagemole, a North Korean Reconnaissance General Bureau-linked cluster overlapping with Lazarus Group's broader fake-recruiter operations) runs a multi-stage social-engineering campaign dubbed 'ClickFake Interview.' Fake recruiter personas contact cryptocurrency, blockchain, and Web3 professionals (roles spanning investment, legal, advisory, business development, and engineering with direct wallet or company account access) via LinkedIn and similar platforms, directing them to React-based skill-assessment sites impersonating real companies such as Coinbase, Robinhood, Uniswap, Kraken, and Parallel Studios (Doodles). After candidates complete a coding/skill quiz, the site presents a fabricated camera or microphone driver error and instructs the victim to 'fix' it by copy-pasting an OS-specific command into a terminal (a ClickFix-style social-engineering technique).
On Windows, the command uses PowerShell Invoke-WebRequest or curl to fetch a ZIP archive containing PylangGhost modules and a Visual Basic Script; the VBScript extracts lib.zip and launches a renamed Python interpreter executing nvidia.py as the RAT's main module, then installs a Registry Run key for persistence across logons. On macOS, an equivalent Bash one-liner downloads a fake 'Intel/NVIDIA driver' ZIP (CodeFixerNow.app / macPatch.sh) containing the Go-compiled GolangGhost binary, and establishes persistence via a Launch Agent plist so the RAT restarts on reboot.
Both variants share near-identical module structure and a compact single-letter/short-code command set (qwer/asdf/zxcv/vbcx/ghdj/r4ys/89io/gi%#/dghh) implementing system-info collection, file upload/download, remote shell, sleep, and staged browser-credential theft. Chrome credential and cookie databases are decrypted using the OS's native credential store (macOS Keychain via the `security` utility on macOS; DPAPI-protected local state on Windows) and exfiltrated to the C2. The RAT enumerates and harvests session/credential data from over 80 browser extensions, explicitly including cryptocurrency wallets (MetaMask, Phantom, Bitski, Initia, TronLink, MultiverseX) and password managers (1Password, NordPass). Uniquely, the malware force-closes Chrome, then rewrites the browser's Secure Preferences file to inject expanded permissions (active-tab access, clipboard write, arbitrary web requests, expanded storage access) directly into the installed MetaMask extension, abusing the wallet's trusted browser-extension position to enable follow-on transaction manipulation or session hijacking without needing to re-authenticate.
C2 communications use HTTP (unencrypted transport) carrying RC4-encrypted payloads, each packet prefixed with a 16-byte MD5 integrity checksum and a 128-byte embedded RC4 key, maintained through a persistent command loop. Infrastructure is disposable and rotated frequently: dozens of typosquatted/fake driver-update and skill-assessment domains front a small pool of VPS-hosted C2 IPs on port 8080. Cisco Talos first documented GolangGhost/the ClickFake Interview campaign in 2025 and later identified the Python-based PylangGhost variant, noting near-identical module design between the two implementations indicative of a shared development team. Reported impact has so far been limited and concentrated among individuals in India, with no confirmed Cisco enterprise customer compromises via telemetry, though the campaign continues to evolve with new infrastructure and lure domains as of the July 2026 reporting.
Weaknesses (CWE)
CWE-522, CWE-311, CWE-494, CWE-829
Target sectors: cryptocurrency, blockchain, finance, web3, technology
Target regions: Global, india, North America
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 42 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1589.002, T1593.001, T1583.001, T1585.001, T1608.001, T1566.002, T1204.001, T1059.001, T1059.004, T1059.006