GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous Chollima / ClickFake Interview)
GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to (TL-2026-1610), also tracked as ClickFake Interview, is a high-severity malware campaign, first published 2026-07-22. It is attributed to WageMole (North Korea) with high confidence, affects Google Chrome Browser, maps to 31 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 42 indicators of compromise.
Key facts for TL-2026-1610
- Threat ID
- TL-2026-1610
- Also known as
- ClickFake Interview, ClickFix Interview Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-22
- Last reviewed
- 2026-07-22
- Attribution
- WageMole
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, blockchain, finance, web3, technology
- Target regions
- Global, india, North America
- Detection rules
- 9
- Indicators of compromise
- 42
Malware and tooling in GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to
Malware and tooling: GolangGhost (OS X), PylangGhost
North Korea-aligned Famous Chollima (Wagemole) is running a fake-recruitment 'ClickFake Interview' campaign against cryptocurrency and Web3 professionals, using a staged camera/microphone-fix ClickFix lure to get victims to paste a malicious Terminal/PowerShell command. This deploys GolangGhost (macOS, Go) or PylangGhost (Windows, Python), which abuses the macOS Keychain and Chrome's local databases to steal credentials/cookies from 80+ browser extensions, specifically hijacking MetaMask by rewriting Chrome's Secure Preferences to grant it expanded permissions.
How GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to works
Famous Chollima (also tracked as Wagemole, a North Korean Reconnaissance General Bureau-linked cluster overlapping with Lazarus Group's broader fake-recruiter operations) runs a multi-stage social-engineering campaign dubbed 'ClickFake Interview.' Fake recruiter personas contact cryptocurrency, blockchain, and Web3 professionals (roles spanning investment, legal, advisory, business development, and engineering with direct wallet or company account access) via LinkedIn and similar platforms, directing them to React-based skill-assessment sites impersonating real companies such as Coinbase, Robinhood, Uniswap, Kraken, and Parallel Studios (Doodles). After candidates complete a coding/skill quiz, the site presents a fabricated camera or microphone driver error and instructs the victim to 'fix' it by copy-pasting an OS-specific command into a terminal (a ClickFix-style social-engineering technique).
On Windows, the command uses PowerShell Invoke-WebRequest or curl to fetch a ZIP archive containing PylangGhost modules and a Visual Basic Script; the VBScript extracts lib.zip and launches a renamed Python interpreter executing nvidia.py as the RAT's main module, then installs a Registry Run key for persistence across logons. On macOS, an equivalent Bash one-liner downloads a fake 'Intel/NVIDIA driver' ZIP (CodeFixerNow.app / macPatch.sh) containing the Go-compiled GolangGhost binary, and establishes persistence via a Launch Agent plist so the RAT restarts on reboot.
Both variants share near-identical module structure and a compact single-letter/short-code command set (qwer/asdf/zxcv/vbcx/ghdj/r4ys/89io/gi%#/dghh) implementing system-info collection, file upload/download, remote shell, sleep, and staged browser-credential theft. Chrome credential and cookie databases are decrypted using the OS's native credential store (macOS Keychain via the `security` utility on macOS; DPAPI-protected local state on Windows) and exfiltrated to the C2. The RAT enumerates and harvests session/credential data from over 80 browser extensions, explicitly including cryptocurrency wallets (MetaMask, Phantom, Bitski, Initia, TronLink, MultiverseX) and password managers (1Password, NordPass). Uniquely, the malware force-closes Chrome, then rewrites the browser's Secure Preferences file to inject expanded permissions (active-tab access, clipboard write, arbitrary web requests, expanded storage access) directly into the installed MetaMask extension, abusing the wallet's trusted browser-extension position to enable follow-on transaction manipulation or session hijacking without needing to re-authenticate.
C2 communications use HTTP (unencrypted transport) carrying RC4-encrypted payloads, each packet prefixed with a 16-byte MD5 integrity checksum and a 128-byte embedded RC4 key, maintained through a persistent command loop. Infrastructure is disposable and rotated frequently: dozens of typosquatted/fake driver-update and skill-assessment domains front a small pool of VPS-hosted C2 IPs on port 8080. Cisco Talos first documented GolangGhost/the ClickFake Interview campaign in 2025 and later identified the Python-based PylangGhost variant, noting near-identical module design between the two implementations indicative of a shared development team. Reported impact has so far been limited and concentrated among individuals in India, with no confirmed Cisco enterprise customer compromises via telemetry, though the campaign continues to evolve with new infrastructure and lure domains as of the July 2026 reporting.
MITRE ATT&CK techniques used in TL-2026-1610
Collection
T1005 Data from Local System; T1115 Clipboard Data; T1560 Archive Collected Data
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.001 PowerShell; T1059.004 Unix Shell; T1059.005 Visual Basic; T1059.006 Python; T1204.001 Malicious Link
Command and Control
T1071.001 Web Protocols; T1571 Non-Standard Port; T1573.001 Symmetric Cryptography
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1518.001 Security Software Discovery
defense-impairment
T1112 Modify Registry; T1647 Plist File Modification
Credential Access
T1539 Steal Web Session Cookie; T1552.001 Credentials In Files; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers
Persistence
T1547.001 Registry Run Keys / Startup Folder
Initial Access
Resource Development
T1583.001 Domains; T1585.001 Social Media Accounts; T1608.001 Upload Malware
Reconnaissance
T1589.002 Email Addresses; T1593.001 Social Media
Impact
Affected products and versions in GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to
- Google — Chrome Browser
Vulnerable versions: all versions storing local credential/cookie databases and Secure Preferences - Consensys — MetaMask Browser Extension
Vulnerable versions: all versions installed in Chrome when Secure Preferences is attacker-writable - Apple — macOS
Vulnerable versions: all versions supporting Bash/Launch Agent execution and Keychain access - Microsoft — Windows
Vulnerable versions: all versions supporting PowerShell/VBScript execution and Registry Run keys
Remediation for GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to
Immediate actions
- Block C2 IPs 31.57.243.29:8080, 154.58.204.15:8080, 212.81.47.217:8080, 31.57.243.190:8080, 95.216.92.207:8080 at perimeter and proxy
- Sinkhole/deny DNS resolution for all listed fake driver-update and fake job-interview domains
- Search endpoint and proxy logs for the listed SHA-256 hashes and for renamed python.exe/python3 processes executing nvidia.py or auto.py
- Force-reset and rotate MetaMask/crypto wallet seed phrases and re-authenticate all password-manager vaults on any host with a hash or C2 match
- Inspect Chrome's Secure Preferences file for unexpected extension permission grants on MetaMask and other wallet/password-manager extensions
- Remove unauthorized Launch Agent plists (macOS) and Registry Run keys referencing python/nvidia/driver-update binaries (Windows)
Workarounds
- Disable clipboard-to-terminal/PowerShell execution via endpoint policy for non-engineering users
- Restrict MetaMask and other wallet extension permissions to minimum required scope via enterprise browser policy
Longer-term hardening
- Deploy EDR with behavioral detection for ClickFix-style clipboard-paste-to-terminal/PowerShell execution
- Enforce browser extension allow-listing and Secure Preferences integrity monitoring on high-value (finance/crypto) endpoints
- Train recruiting-adjacent and Web3/crypto staff on ClickFake Interview social engineering and fake camera/mic 'fix' terminal prompts
- Implement hardware wallets / transaction-signing devices for treasury and high-value wallet operations to reduce browser-extension blast radius
- Monitor for newly registered typosquatted recruitment and driver-update domains impersonating the organization's brand or major crypto platforms
Weaknesses (CWE) in GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to
CWE-522, CWE-311, CWE-494, CWE-829
Timeline of GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to
- ClickFix-style fake error/terminal-paste social engineering tactic begins appearing in DPRK-aligned fake-recruiter campaigns preceding GolangGhost's identification.
- Cisco Talos identifies the GolangGhost (Go-compiled) RAT deployed against macOS users via the ClickFake Interview fake job-assessment sites.
- Cisco Talos publicly discloses PylangGhost, a Python-based Windows variant of GolangGhost sharing near-identical module structure, expanding the campaign to Windows targets.
- Additional vendor and OSINT reporting (PolySwarm, eSentry, Infosecurity Magazine, ANY.RUN) documents expanded IOC sets, RAT command set, and 80+ targeted browser extensions including MetaMask, Phantom, TronLink, 1Password and NordPass.
- SOCRadar publishes attribution analysis linking the ClickFake Interview campaign to Famous Chollima / Wagemole and North Korea's Reconnaissance General Bureau, noting concentrated impact in India.
- Public malware-removal guidance for GolangGhost RAT on macOS is published as the campaign continues circulating.
- Threat tracked as TL-2026-1610 by the Threadlinqs Intelligence Platform based on the July 2026 Cyber Security News reporting and cross-referenced prior Talos/SOCRadar/PolySwarm research.
- Cyber Security News reports an evolved capability: GolangGhost/PylangGhost now abuses macOS Keychain to decrypt Chrome's local credential database and rewrites Chrome's Secure Preferences file to inject expanded permissions directly into the MetaMask extension.
Sources cited for GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to
- GolangGhost Malware Steals Chrome Secrets
- Famous Chollima deploying Python version of GolangGhost RAT
- Chollima Hackers Target Windows and MacOS with New GolangGhost RAT Malware
- GolangGhost RAT: Chollima Hackers Strike Both Windows and MacOS Systems
- Famous Chollima's PylangGhost
- Chollima's Python Trap: PyLangGhost RAT Haunts Crypto & Finance
- North Korean Hackers Deploy Python-Based Trojan Targeting Crypto
- PyLangGhost RAT: Rising Data Stealer from Lazarus Group Targeting Finance and Technology
- DPRK's Famous Chollima Deploys RATs Through ClickFake Job Interviews
- GolangGhost RAT (Mac) - Removal steps, and macOS cleanup
Threats related to GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to
- North Korea-Linked "Contagious Interview"/Famous Chollima Actors Hide JavaScript Loaders (PolinRider) in Open-Source Packages
- PolinRider: DPRK Supply-Chain Campaign Hides BeaverTail/InvisibleFerret Malware in JS Build Config Files (tailwind.config.js et al.)
- Void Dokkaebi (Contagious Interview / Famous Chollima) — DPRK Fake Job Interview Campaign Delivering BeaverTail, InvisibleFerret, OtterCookie & GolangGhost via Trojanized Code Repositories
- Typosquatted npm Package postcss-minify-selector-parser Delivers Nuitka-Compiled Windows RAT with RC4-Encrypted HTTP C2
Detection coverage for TL-2026-1610
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1610 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1610
8 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.