CONTACT FOR ADS

BTCinsider – Bitcoin, Blockchain & DeFi News
  • BOOKMARKS
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
    CryptoShow More
    Nasdaq-Listed Healthcare Firm Opens Bitcoin Treasury With $20 Million BTC Buy
    Nasdaq-Listed Healthcare Firm Opens Bitcoin Treasury With $20 Million BTC Buy
    20.06.2025
    Solana Will Flip Ethereum, Anthony Scaramucci Predicts
    Solana Will Flip Ethereum, Anthony Scaramucci Predicts
    19.06.2025
    How Will Bitcoin Defend Against Quantum Computing? This Project Just Raised $6M
    How Will Bitcoin Defend Against Quantum Computing? This Project Just Raised $6M
    19.06.2025
    Bitcoin Sidechain Plasma Eyes 'Late Summer' Mainnet Launch Following Massive ICO
    Bitcoin Sidechain Plasma Eyes ‘Late Summer’ Mainnet Launch Following Massive ICO
    19.06.2025
    1inch Foundation Proposes User Compensation Plan Following October Hack
    1inch Foundation Proposes User Compensation Plan Following October Hack
    19.06.2025
  • DeFi
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
    MarketShow More
    Bitcoin Cash Stages Surprise Run to Near $500 as Volumes Spike 500%
    Bitcoin Cash Stages Surprise Run to Near $500 as Volumes Spike 500%
    20.06.2025
    TikTok denies TRUMP memecoin buys in reply to congressman’s accusations
    TikTok denies TRUMP memecoin buys in reply to congressman’s accusations
    20.06.2025
    XRP Early Buyers Accelerate Profit-Taking as Regulatory Wins Bolster XRP Ecosystem
    XRP Early Buyers Accelerate Profit-Taking as Regulatory Wins Bolster XRP Ecosystem
    20.06.2025
    Apple eyes generative AI to speed up custom chip design: Report
    Apple eyes generative AI to speed up custom chip design: Report
    20.06.2025
    Trump Family Reduces Stake in Crypto Project World Liberty
    Trump Family Reduces Stake in Crypto Project World Liberty
    20.06.2025
  • News
    • Mining
    • NFT
    • Stocks
    • Web3
    • Tech
    NewsShow More
    A16z-backed Spekter Games founder shares Telegram gaming ethos
    A16z-backed Spekter Games founder shares Telegram gaming ethos
    20.06.2025
    Avalanche Game 'Forgotten Playland' Implements NFTs in Biggest Update Yet
    Avalanche Game ‘Forgotten Playland’ Implements NFTs in Biggest Update Yet
    19.06.2025
    Ethereum to $80,000? An unabashed booster makes his case
    Ethereum to $80,000? An unabashed booster makes his case
    19.06.2025
    B3 acquires PC startup, unveils desktop with ‘Destroy’ button
    B3 acquires PC startup, unveils desktop with ‘Destroy’ button
    19.06.2025
    Sandeep Nailwal’s Polygon takeover is his chance to ‘go all in’
    Sandeep Nailwal’s Polygon takeover is his chance to ‘go all in’
    18.06.2025
  • Contact Us
Reading: North Korean Hackers Are Targeting Top Crypto Firms With Malware Hidden in Job Applications
Share
  • bitcoinBitcoin(BTC)$106,039.34
  • ethereumEthereum(ETH)$2,553.47
  • tetherTether USDt(USDT)$1.00
  • rippleXRP(XRP)$2.17
  • binancecoinBNB(BNB)$649.09
  • solanaSolana(SOL)$147.60
  • usd-coinUSDC(USDC)$1.00
  • tronTRON(TRX)$0.273355
  • dogecoinDogecoin(DOGE)$0.170472
  • cardanoCardano(ADA)$0.60
Font ResizerAa
BTCinsider – Bitcoin, Blockchain & DeFi NewsBTCinsider – Bitcoin, Blockchain & DeFi News
  • Home
  • Crypto
  • Market
  • News
  • Tech
  • Contact
Search
  • Home
  • Market
    • Business
    • Investor
  • Tech
  • News
    • Web3
    • NFT
  • DeFi
  • Crypto
Have an existing account? Sign In
Follow US
© All Rights Reserved.
Tech

North Korean Hackers Are Targeting Top Crypto Firms With Malware Hidden in Job Applications

Roman Hasley
Last updated: 20.06.2025 12:15 PM
Roman Hasley
Published: 20.06.2025
Share
North Korean Hackers Are Targeting Top Crypto Firms With Malware Hidden in Job Applications

A North Korean hacking group is targeting crypto workers with a Python-based malware disguised as part of a fake job application process, researchers at Cisco Talos said earlier this week.

Most victims appear to be based in India, according to open-source signals, and seem to be individuals with prior experience in blockchain and cryptocurrency startups.

While Cisco reports no evidence of internal compromise, the broader risk remains clear: That these efforts are trying to gain access to the companies these individuals might eventually join.

The malware, called PylangGhost, is a new variant of the previously documented GolangGhost remote access trojan (RAT), and shares most of the same features — just rewritten in Python to better target Windows systems.

Mac users continue to be affected by the Golang version, while Linux systems appear to be unaffected. The threat actor behind the campaign, known as Famous Chollima, has been active since mid-2024 and is believed to be a DPRK-aligned group.

Their latest attack vector is simple: impersonate top crypto firms like Coinbase, Robinhood, and Uniswap through highly polished fake career sites, and lure software engineers, marketers, and designers into completing staged “skill tests.”

Once a target fills in basic information and answers technical questions, they’re prompted to install fake video drivers by pasting a command into their terminal, which quietly downloads and launches the Python-based RAT.

(Cisco Telos)

(Cisco Telos)

The payload is hidden in a ZIP file that includes the renamed Python interpreter (nvidia.py), a Visual Basic script to unpack the archive, and six core modules responsible for persistence, system fingerprinting, file transfer, remote shell access, and browser data theft.

The RAT pulls login credentials, session cookies, and wallet data from over 80 extensions, including MetaMask, Phantom, TronLink, and 1Password.

The command set allows full remote control of infected machines, including file uploads, downloads, system recon, and launching a shell — all routed through RC4-encrypted HTTP packets.

RC4-encrypted HTTP packets are data sent over the internet that are scrambled using an outdated encryption method called RC4. Even though the connection itself isn’t secure (HTTP), the data inside is encrypted, but not very well, since RC4 is outdated and easily broken by today’s standards.

Despite being a rewrite, the structure and naming conventions of PylangGhost mirror those of GolangGhost almost exactly, suggesting both were likely authored by the same operator, Cisco said.

The Protocol: Polygon, Once a Scaling Leader, Eyes a Revamp
Humanoid AI-powered robots duke it out in China fight comp
Elon Musk Says New XChat Is Coming With ‘Bitcoin Style’ Encryption
Polygon’s Sandeep Nailwal Takes Over as Foundation CEO Amid Strategic Shakeup
US wants $7.7M in crypto laundered in North Korea IT worker plot

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Telegram Email Copy Link Print
Share
Previous Article TikTok denies TRUMP memecoin buys in reply to congressman’s accusations TikTok denies TRUMP memecoin buys in reply to congressman’s accusations
Next Article Bitcoin Cash Stages Surprise Run to Near $500 as Volumes Spike 500% Bitcoin Cash Stages Surprise Run to Near $500 as Volumes Spike 500%
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Curve Founder Warns of 'For-Hire' Hackers Coordinating Cross-Platform Attacks
Curve Founder Warns of ‘For-Hire’ Hackers Coordinating Cross-Platform Attacks
'Dogecoin Millionaire' Is Now a Pepe Millionaire—And He’s Stacking These Meme Coins Next
‘Dogecoin Millionaire’ Is Now a Pepe Millionaire—And He’s Stacking These Meme Coins Next
Performance Art Duo Operator 'Make Movement Collectible' With NFTs
Performance Art Duo Operator ‘Make Movement Collectible’ With NFTs

You Might Also Like

Shift to digital asset technology won't be 'slow' — Franklin Templeton CEO
Tech

Shift to digital asset technology won't be 'slow' — Franklin Templeton CEO

13.06.2025
RISE Chain Secures $4M From Galaxy to Power Ultra-Fast Layer-2
Tech

RISE Chain Secures $4M From Galaxy to Power Ultra-Fast Layer-2

09.06.2025
Is Free Will an Illusion? Quantum Experiments Aim to Find Out
Tech

Is Free Will an Illusion? Quantum Experiments Aim to Find Out

10.06.2025
Project Eleven Raises $6M to Defend Bitcoin From the Coming Quantum Threat
Tech

Project Eleven Raises $6M to Defend Bitcoin From the Coming Quantum Threat

19.06.2025

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

BTCinsider – Bitcoin, Blockchain & DeFi News

With 20 million users, we are the #1 global business blockchain and cryptocurrency news network.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad image
© All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up