GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous Chollima / ClickFake Interview)

GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to (TL-2026-1610), also tracked as ClickFake Interview, is a high-severity malware campaign, first published 2026-07-22. It is attributed to WageMole (North Korea) with high confidence, affects Google Chrome Browser, maps to 31 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 42 indicators of compromise.

Key facts for TL-2026-1610

Threat ID
TL-2026-1610
Also known as
ClickFake Interview, ClickFix Interview Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-22
Last reviewed
2026-07-22
Attribution
WageMole
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
cryptocurrency, blockchain, finance, web3, technology
Target regions
Global, india, North America
Detection rules
9
Indicators of compromise
42

Malware and tooling in GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to

Malware and tooling: GolangGhost (OS X), PylangGhost

North Korea-aligned Famous Chollima (Wagemole) is running a fake-recruitment 'ClickFake Interview' campaign against cryptocurrency and Web3 professionals, using a staged camera/microphone-fix ClickFix lure to get victims to paste a malicious Terminal/PowerShell command. This deploys GolangGhost (macOS, Go) or PylangGhost (Windows, Python), which abuses the macOS Keychain and Chrome's local databases to steal credentials/cookies from 80+ browser extensions, specifically hijacking MetaMask by rewriting Chrome's Secure Preferences to grant it expanded permissions.

How GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to works

Famous Chollima (also tracked as Wagemole, a North Korean Reconnaissance General Bureau-linked cluster overlapping with Lazarus Group's broader fake-recruiter operations) runs a multi-stage social-engineering campaign dubbed 'ClickFake Interview.' Fake recruiter personas contact cryptocurrency, blockchain, and Web3 professionals (roles spanning investment, legal, advisory, business development, and engineering with direct wallet or company account access) via LinkedIn and similar platforms, directing them to React-based skill-assessment sites impersonating real companies such as Coinbase, Robinhood, Uniswap, Kraken, and Parallel Studios (Doodles). After candidates complete a coding/skill quiz, the site presents a fabricated camera or microphone driver error and instructs the victim to 'fix' it by copy-pasting an OS-specific command into a terminal (a ClickFix-style social-engineering technique).

On Windows, the command uses PowerShell Invoke-WebRequest or curl to fetch a ZIP archive containing PylangGhost modules and a Visual Basic Script; the VBScript extracts lib.zip and launches a renamed Python interpreter executing nvidia.py as the RAT's main module, then installs a Registry Run key for persistence across logons. On macOS, an equivalent Bash one-liner downloads a fake 'Intel/NVIDIA driver' ZIP (CodeFixerNow.app / macPatch.sh) containing the Go-compiled GolangGhost binary, and establishes persistence via a Launch Agent plist so the RAT restarts on reboot.

Both variants share near-identical module structure and a compact single-letter/short-code command set (qwer/asdf/zxcv/vbcx/ghdj/r4ys/89io/gi%#/dghh) implementing system-info collection, file upload/download, remote shell, sleep, and staged browser-credential theft. Chrome credential and cookie databases are decrypted using the OS's native credential store (macOS Keychain via the `security` utility on macOS; DPAPI-protected local state on Windows) and exfiltrated to the C2. The RAT enumerates and harvests session/credential data from over 80 browser extensions, explicitly including cryptocurrency wallets (MetaMask, Phantom, Bitski, Initia, TronLink, MultiverseX) and password managers (1Password, NordPass). Uniquely, the malware force-closes Chrome, then rewrites the browser's Secure Preferences file to inject expanded permissions (active-tab access, clipboard write, arbitrary web requests, expanded storage access) directly into the installed MetaMask extension, abusing the wallet's trusted browser-extension position to enable follow-on transaction manipulation or session hijacking without needing to re-authenticate.

C2 communications use HTTP (unencrypted transport) carrying RC4-encrypted payloads, each packet prefixed with a 16-byte MD5 integrity checksum and a 128-byte embedded RC4 key, maintained through a persistent command loop. Infrastructure is disposable and rotated frequently: dozens of typosquatted/fake driver-update and skill-assessment domains front a small pool of VPS-hosted C2 IPs on port 8080. Cisco Talos first documented GolangGhost/the ClickFake Interview campaign in 2025 and later identified the Python-based PylangGhost variant, noting near-identical module design between the two implementations indicative of a shared development team. Reported impact has so far been limited and concentrated among individuals in India, with no confirmed Cisco enterprise customer compromises via telemetry, though the campaign continues to evolve with new infrastructure and lure domains as of the July 2026 reporting.

MITRE ATT&CK techniques used in TL-2026-1610

Collection

T1005 Data from Local System; T1115 Clipboard Data; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.001 PowerShell; T1059.004 Unix Shell; T1059.005 Visual Basic; T1059.006 Python; T1204.001 Malicious Link

Command and Control

T1071.001 Web Protocols; T1571 Non-Standard Port; T1573.001 Symmetric Cryptography

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1518.001 Security Software Discovery

defense-impairment

T1112 Modify Registry; T1647 Plist File Modification

Credential Access

T1539 Steal Web Session Cookie; T1552.001 Credentials In Files; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers

Persistence

T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1585.001 Social Media Accounts; T1608.001 Upload Malware

Reconnaissance

T1589.002 Email Addresses; T1593.001 Social Media

Impact

T1657 Financial Theft

Affected products and versions in GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to

  • Google — Chrome Browser
    Vulnerable versions: all versions storing local credential/cookie databases and Secure Preferences
  • Consensys — MetaMask Browser Extension
    Vulnerable versions: all versions installed in Chrome when Secure Preferences is attacker-writable
  • Apple — macOS
    Vulnerable versions: all versions supporting Bash/Launch Agent execution and Keychain access
  • Microsoft — Windows
    Vulnerable versions: all versions supporting PowerShell/VBScript execution and Registry Run keys

Remediation for GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to

Immediate actions

  • Block C2 IPs 31.57.243.29:8080, 154.58.204.15:8080, 212.81.47.217:8080, 31.57.243.190:8080, 95.216.92.207:8080 at perimeter and proxy
  • Sinkhole/deny DNS resolution for all listed fake driver-update and fake job-interview domains
  • Search endpoint and proxy logs for the listed SHA-256 hashes and for renamed python.exe/python3 processes executing nvidia.py or auto.py
  • Force-reset and rotate MetaMask/crypto wallet seed phrases and re-authenticate all password-manager vaults on any host with a hash or C2 match
  • Inspect Chrome's Secure Preferences file for unexpected extension permission grants on MetaMask and other wallet/password-manager extensions
  • Remove unauthorized Launch Agent plists (macOS) and Registry Run keys referencing python/nvidia/driver-update binaries (Windows)

Workarounds

  • Disable clipboard-to-terminal/PowerShell execution via endpoint policy for non-engineering users
  • Restrict MetaMask and other wallet extension permissions to minimum required scope via enterprise browser policy

Longer-term hardening

  • Deploy EDR with behavioral detection for ClickFix-style clipboard-paste-to-terminal/PowerShell execution
  • Enforce browser extension allow-listing and Secure Preferences integrity monitoring on high-value (finance/crypto) endpoints
  • Train recruiting-adjacent and Web3/crypto staff on ClickFake Interview social engineering and fake camera/mic 'fix' terminal prompts
  • Implement hardware wallets / transaction-signing devices for treasury and high-value wallet operations to reduce browser-extension blast radius
  • Monitor for newly registered typosquatted recruitment and driver-update domains impersonating the organization's brand or major crypto platforms

Weaknesses (CWE) in GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to

CWE-522, CWE-311, CWE-494, CWE-829

Timeline of GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to

  • ClickFix-style fake error/terminal-paste social engineering tactic begins appearing in DPRK-aligned fake-recruiter campaigns preceding GolangGhost's identification.
  • Cisco Talos identifies the GolangGhost (Go-compiled) RAT deployed against macOS users via the ClickFake Interview fake job-assessment sites.
  • Cisco Talos publicly discloses PylangGhost, a Python-based Windows variant of GolangGhost sharing near-identical module structure, expanding the campaign to Windows targets.
  • Additional vendor and OSINT reporting (PolySwarm, eSentry, Infosecurity Magazine, ANY.RUN) documents expanded IOC sets, RAT command set, and 80+ targeted browser extensions including MetaMask, Phantom, TronLink, 1Password and NordPass.
  • SOCRadar publishes attribution analysis linking the ClickFake Interview campaign to Famous Chollima / Wagemole and North Korea's Reconnaissance General Bureau, noting concentrated impact in India.
  • Public malware-removal guidance for GolangGhost RAT on macOS is published as the campaign continues circulating.
  • Threat tracked as TL-2026-1610 by the Threadlinqs Intelligence Platform based on the July 2026 Cyber Security News reporting and cross-referenced prior Talos/SOCRadar/PolySwarm research.
  • Cyber Security News reports an evolved capability: GolangGhost/PylangGhost now abuses macOS Keychain to decrypt Chrome's local credential database and rewrites Chrome's Secure Preferences file to inject expanded permissions directly into the MetaMask extension.

Sources cited for GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to

Threats related to GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to

Detection coverage for TL-2026-1610

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1610 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1610

8 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats