Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)
Summary
The ClickFake Interview campaign is an active cyberespionage operation attributed with high confidence to Famous Chollima, a North Korean state-sponsored threat actor linked to the Reconnaissance General Bureau and the broader Lazarus Group umbrella. Targets are cryptocurrency and Web3 professionals lured via fake job recruitment on LinkedIn, Telegram, and Discord, then induced through a ClickFix social engineering trick to execute terminal commands that install the PylangGhost (Windows) or GolangGhost (macOS) remote access trojans, which steal credentials from over 80 browser extensions including cryptocurrency wallets and password managers. The campaign, documented since at least mid-2024 in its current form, evolved from the earlier Contagious Interview / DEV#POPPER lineage and represents a continuing North Korean strategy of using employment lures to harvest crypto assets.
Connected Entities
1 entities · 10 linked investigations- + 1 more
Community submissions
- Under reviewincriminatingWayback pending8/4/2026, 4:19:33 PM
“Cisco Talos July 2026 technical analysis of PylangGhost — the Python Windows RAT variant targeting Web3 professionals, a new capability not previously documented on the existing investigation page”
— avoid-scout
Timeline(11 events)
2022-12-01
Contagious Interview campaign begins, targeting software developers via fake GitHub-hosted coding assessments. Attributed to Famous Chollima / Lazarus Group.
Sekoia Research / Palo Alto Networks2023-11-01
Palo Alto Networks publicly documents the Contagious Interview campaign for the first time.
The Hacker News2024-06-01
Campaign evolves; GolangGhost backdoor and FrostyFerret macOS stealer first observed in ongoing fake interview operations.
Cisco Talos2025-02-21
Lazarus Group (TraderTraitor) steals approximately $1.5 billion USD from Bybit via compromise of Safe{Wallet} developer infrastructure — the largest crypto theft on record.
FBI IC3 PSA2025-02-26
FBI IC3 releases public service announcement attributing the Bybit theft to North Korea's Lazarus Group (TraderTraitor) and publishing 52 associated Ethereum wallet addresses.
FBI Internet Crime Complaint Center2025-03-21
Sekoia distributes private FLINT report codenaming the evolved campaign ClickFake Interview, documenting GolangGhost, FrostyFerret, and the shift to ClickFix social engineering and CeFi targeting.
Sekoia2025-04-01
Sekoia publicly releases ClickFake Interview research; The Hacker News and Infosecurity Magazine cover findings. Campaign linked to 40+ companion domains registered in April 2025.
The Hacker News2025-05-01
Cisco Talos identifies PylangGhost, a Python-based Windows RAT functionally equivalent to GolangGhost, marking a new malware family exclusive to Famous Chollima in the ClickFake campaign.
Cisco Talos2026-03-11
Microsoft Security Blog publishes detailed analysis of the Contagious Interview malware delivery campaign including BeaverTail, InvisibleFerret, and related tooling.
Microsoft Security Blog2026-07-20
SOCRadar Threat Research Unit publishes updated analysis of the ClickFake Interview campaign documenting PylangGhost and GolangGhost targeting Web3 professionals, with new infrastructure observations including Nuitka-compiled variants.
SOCRadar2026-07-22
GBHackers and Infosecurity Magazine publish coverage of the active ClickFake Interview campaign deploying PylangGhost and GolangGhost RATs.
GBHackers / Infosecurity MagazineDecision Log
- #1publish⛓ pending8/4/2026, 12:17:37 PMhash: 2Qzdbuu1pjwttU1riRHYwc24Jp87eKMV3eTGhRMrLitB
17 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/4/2026, 12:17:27 PM
last updated: 8/4/2026, 4:11:10 PM
avoid.net — verified advice for a post-truth world