North Korean Hackers Target Web3 Pros with 'ClickFake' Campaign: How to Stay Safe (2026)

The world of Web3 and cryptocurrency is under threat from a sophisticated new campaign dubbed 'ClickFake' by researchers at SOCRadar. This operation, attributed to the North Korean-aligned hacking group Famous Chollima, is a masterclass in social engineering, targeting professionals in the field with highly personalized recruitment scams. What makes this campaign particularly insidious is its ability to leverage real-time monitoring and psychometrics to build trust and authenticity, making it difficult for victims to detect the deception. The attack begins on mainstream professional networks and communication platforms, including LinkedIn, Telegram, Discord, and direct email. Posing as recruiters from reputable firms or creating entirely fictitious web companies, the actors reach out to developers and administrators, enticing them with highly lucrative salary packages and prestigious career advancements. Once the target agrees to the assessment, they are directed to a specialized online platform controlled by the attackers. These malicious web interfaces utilize real-time monitoring and psychometrics to build authenticity. They feature strict gating mechanisms, display tailored interview questions based on the candidate's advertised role, and incorporate countdown timers to create psychological pressure. The core of the deception lies in a technique known as ClickFix. While the candidate is performing the assessment, the platform artificially triggers a simulated error, claiming that the system cannot access the user's camera or microphone. To resolve the issue and continue with the interview, the page displays a helpful prompt instructing the candidate to copy and paste a diagnostic command into their system terminal. This command initiates a complex infection chain, depending on the operating system. For Windows users, the script utilizes native system utilities like PowerShell or curl to fetch a compressed ZIP archive from the attacker's server, which then unpacks a Python runtime and loads PylangGhost, a highly customized RAT. For macOS users, the attack path is similarly streamlined but uses a different programming language. The malicious terminal command fetches and executes GolangGhost, a remote access trojan written in Go. On Apple devices, the infection process often installs the primary payload alongside a credential-harvesting helper application built with SwiftUI, which is specifically designed to trick macOS users into surrendering their administrative passwords. Both PylangGhost and GolangGhost are built on a highly modular architecture, consisting of six interconnected parts: a main orchestrator, a dedicated configuration holder, an archive helper, a command launcher, a command-and-control (C2) communications module, and a specialized data stealer. The primary objective of this dual-headed malware suite is financial gain through asset theft. The integrated stealer module targets more than 80 distinct browser extensions and is specifically programmed to harvest session data, saved credentials, and private keys from widely used cryptocurrency wallets such as MetaMask, Phantom, and TronLink, as well as commercial password managers like NordPass. Because many Web3 professionals manage corporate infrastructure using browser-based tools, a single successful intrusion can grant attackers access to millions of dollars in digital assets. To keep their operations running, Famous Chollima rapidly register domains using budget-friendly registrars like Hostinger and NameCheap. They prioritize speed and sheer volume, spinning up new assessment portals as quickly as defenders can blacklist the old ones. They also implement precise targeting controls, such as blocking mobile devices and validating individual invitation links, to prevent automated malware sandboxes and security analysts from studying their payload delivery mechanisms. In a July 2023 report, the SOCRadar Threat Research Unit (STRU) researchers noted that this campaign is not only a risk to individuals but also to organizations. They wrote, 'The actors also seek indirect access to pivot toward company funds, which makes it equally alarming for organizations, since recent reports state that 'one in three employees admit to using company tech to apply for jobs, interview, or do work for other companies.' This raises a deeper question about the security of corporate infrastructure and the potential for insider threats. The ClickFake campaign is a stark reminder of the evolving nature of cyber threats and the need for constant vigilance and adaptation in the face of sophisticated social engineering tactics.

North Korean Hackers Target Web3 Pros with 'ClickFake' Campaign: How to Stay Safe (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Chrissy Homenick

Last Updated:

Views: 5976

Rating: 4.3 / 5 (54 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Chrissy Homenick

Birthday: 2001-10-22

Address: 611 Kuhn Oval, Feltonbury, NY 02783-3818

Phone: +96619177651654

Job: Mining Representative

Hobby: amateur radio, Sculling, Knife making, Gardening, Watching movies, Gunsmithing, Video gaming

Introduction: My name is Chrissy Homenick, I am a tender, funny, determined, tender, glorious, fancy, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.