CONTACT FOR ADS

BTCinsider – Bitcoin, Blockchain & DeFi News
  • BOOKMARKS
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
    CryptoShow More
    Nasdaq-Listed Healthcare Firm Opens Bitcoin Treasury With $20 Million BTC Buy
    Nasdaq-Listed Healthcare Firm Opens Bitcoin Treasury With $20 Million BTC Buy
    20.06.2025
    Solana Will Flip Ethereum, Anthony Scaramucci Predicts
    Solana Will Flip Ethereum, Anthony Scaramucci Predicts
    19.06.2025
    How Will Bitcoin Defend Against Quantum Computing? This Project Just Raised $6M
    How Will Bitcoin Defend Against Quantum Computing? This Project Just Raised $6M
    19.06.2025
    Bitcoin Sidechain Plasma Eyes 'Late Summer' Mainnet Launch Following Massive ICO
    Bitcoin Sidechain Plasma Eyes ‘Late Summer’ Mainnet Launch Following Massive ICO
    19.06.2025
    1inch Foundation Proposes User Compensation Plan Following October Hack
    1inch Foundation Proposes User Compensation Plan Following October Hack
    19.06.2025
  • DeFi
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
    MarketShow More
    TikTok denies TRUMP memecoin buys in reply to congressman’s accusations
    TikTok denies TRUMP memecoin buys in reply to congressman’s accusations
    20.06.2025
    XRP Early Buyers Accelerate Profit-Taking as Regulatory Wins Bolster XRP Ecosystem
    XRP Early Buyers Accelerate Profit-Taking as Regulatory Wins Bolster XRP Ecosystem
    20.06.2025
    Apple eyes generative AI to speed up custom chip design: Report
    Apple eyes generative AI to speed up custom chip design: Report
    20.06.2025
    Trump Family Reduces Stake in Crypto Project World Liberty
    Trump Family Reduces Stake in Crypto Project World Liberty
    20.06.2025
    Bitcoin ‘weak hands’ sell 15K BTC at a loss: Are BTC lows under $100K next?
    Bitcoin ‘weak hands’ sell 15K BTC at a loss: Are BTC lows under $100K next?
    20.06.2025
  • News
    • Mining
    • NFT
    • Stocks
    • Web3
    • Tech
    NewsShow More
    A16z-backed Spekter Games founder shares Telegram gaming ethos
    A16z-backed Spekter Games founder shares Telegram gaming ethos
    20.06.2025
    Avalanche Game 'Forgotten Playland' Implements NFTs in Biggest Update Yet
    Avalanche Game ‘Forgotten Playland’ Implements NFTs in Biggest Update Yet
    19.06.2025
    Ethereum to $80,000? An unabashed booster makes his case
    Ethereum to $80,000? An unabashed booster makes his case
    19.06.2025
    B3 acquires PC startup, unveils desktop with ‘Destroy’ button
    B3 acquires PC startup, unveils desktop with ‘Destroy’ button
    19.06.2025
    Sandeep Nailwal’s Polygon takeover is his chance to ‘go all in’
    Sandeep Nailwal’s Polygon takeover is his chance to ‘go all in’
    18.06.2025
  • Contact Us
Reading: North Korea targets crypto workers with new info-stealing malware
Share
  • bitcoinBitcoin(BTC)$106,039.34
  • ethereumEthereum(ETH)$2,553.47
  • tetherTether USDt(USDT)$1.00
  • rippleXRP(XRP)$2.17
  • binancecoinBNB(BNB)$649.09
  • solanaSolana(SOL)$147.60
  • usd-coinUSDC(USDC)$1.00
  • tronTRON(TRX)$0.273355
  • dogecoinDogecoin(DOGE)$0.170472
  • cardanoCardano(ADA)$0.60
Font ResizerAa
BTCinsider – Bitcoin, Blockchain & DeFi NewsBTCinsider – Bitcoin, Blockchain & DeFi News
  • Home
  • Crypto
  • Market
  • News
  • Tech
  • Contact
Search
  • Home
  • Market
    • Business
    • Investor
  • Tech
  • News
    • Web3
    • NFT
  • DeFi
  • Crypto
Have an existing account? Sign In
Follow US
© All Rights Reserved.
Business

North Korea targets crypto workers with new info-stealing malware

Roman Hasley
Last updated: 20.06.2025 7:31 AM
Roman Hasley
Published: 20.06.2025
Share
North Korea targets crypto workers with new info-stealing malware

Crypto Job Lures Lead to Malware Infections by North Korean Actors

Cisco Talos reports on a new RAT targeting cryptocurrency job seekers.

North Korean-aligned threat actors have been targeting job seekers in the cryptocurrency industry with a new remote access trojan (RAT), identified as “PylangGhost” by Cisco Talos.

According to the report published on Wednesday, PylangGhost is linked to the hacking collective known as “Famous Chollima” or “Wagemole.”

“Based on the advertised positions, it is clear that Famous Chollima is broadly targeting individuals with previous experience in cryptocurrency and blockchain technologies.”

Fake Job Sites and Tests a Cover for Malware

Fraudulent job sites impersonating legitimate companies like Coinbase, Robinhood, and Uniswap were used to initiate attacks.

Fraudulent job sites and skill-testing campaigns were employed as part of a multi-stage social engineering campaign.

Sample of fake job website. Source: Cisco Talos
Sample of fake job website. Source: Cisco Talos

Victims were tricked into enabling camera access and installing malicious drivers under the guise of video interviews, leading to device compromise.

Payload Targets Crypto Wallets

PylangGhost, a Python-based variant of the previously known GolangGhost RAT, enables remote device control and steals credentials from numerous browser extensions.

Upon execution, the malware steals cookies and credentials from password managers and cryptocurrency wallets including MetaMask, 1Password, Phantom, and others.

Instructions to download the payload. Source: Cisco Talos
Instructions to download the payload. Source: Cisco Talos

Multitasking Malware Capabilities

The malware offers extensive remote access and data exfiltration capabilities, including screenshot capture, file management, browser data theft, and system information gathering.

Cisco Talos noted the lack of AI model assistance in code comments, suggesting human authorship.

Fake Job Lures Not New

This tactic is consistent with known North Korean cybercrime patterns.

Similar recruitment-based attacks previously targeted crypto developers following the $1.4 billion Bybit exchange heist in April.

A Startup Is Looking to Pay 30% Yield by Tokenizing AI Infrastructure
Eric Trump is 'biggest fan' of Justin Sun, but denies involvement in Tron’s public venture
Société Générale launches US dollar stablecoin on Ethereum and Solana
Ondo Finance Debuts $693M Treasury Token on XRP Ledger Amid Soaring RWA Trend
Sam Altman’s World Chain Adds Native USDC Stablecoin and Circle’s Cross-Chain Service

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Telegram Email Copy Link Print
Share
Previous Article Dogecoin Steady But Flashing 'Oversold' in Signal for Bearish Bets Dogecoin Steady But Flashing ‘Oversold’ in Signal for Bearish Bets
Next Article Bitcoin ‘weak hands’ sell 15K BTC at a loss: Are BTC lows under $100K next? Bitcoin ‘weak hands’ sell 15K BTC at a loss: Are BTC lows under $100K next?
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Curve Founder Warns of 'For-Hire' Hackers Coordinating Cross-Platform Attacks
Curve Founder Warns of ‘For-Hire’ Hackers Coordinating Cross-Platform Attacks
'Dogecoin Millionaire' Is Now a Pepe Millionaire—And He’s Stacking These Meme Coins Next
‘Dogecoin Millionaire’ Is Now a Pepe Millionaire—And He’s Stacking These Meme Coins Next
Performance Art Duo Operator 'Make Movement Collectible' With NFTs
Performance Art Duo Operator ‘Make Movement Collectible’ With NFTs

You Might Also Like

Ex-Google Chief Eric Schmidt Backs Firms Behind Blockchain Credit Bureau
Business

Ex-Google Chief Eric Schmidt Backs Firms Behind Blockchain Credit Bureau

10.06.2025
Cycles eyes sustainable crypto credit after 2022 liquidity crisis
Business

Cycles eyes sustainable crypto credit after 2022 liquidity crisis

17.06.2025
UK's OpenTrade Raises $7M to Expand Stablecoin Yield Access in Inflation-Hit Markets
Business

UK’s OpenTrade Raises $7M to Expand Stablecoin Yield Access in Inflation-Hit Markets

11.06.2025
a16z Bets Big on EigenLayer Again With $70M Token Buy to Back ‘EigenCloud’ Launch
Business

a16z Bets Big on EigenLayer Again With $70M Token Buy to Back ‘EigenCloud’ Launch

17.06.2025

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

BTCinsider – Bitcoin, Blockchain & DeFi News

With 20 million users, we are the #1 global business blockchain and cryptocurrency news network.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad image
© All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up