Skip to main content
Sign in

Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)

avoid.net/famous-chollima-clickfake-interview-campaign-pylangghost-golangghost0/100·93% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

The ClickFake Interview campaign is an active cyberespionage operation attributed with high confidence to Famous Chollima, a North Korean state-sponsored threat actor linked to the Reconnaissance General Bureau and the broader Lazarus Group umbrella. Targets are cryptocurrency and Web3 professionals lured via fake job recruitment on LinkedIn, Telegram, and Discord, then induced through a ClickFix social engineering trick to execute terminal commands that install the PylangGhost (Windows) or GolangGhost (macOS) remote access trojans, which steal credentials from over 80 browser extensions including cryptocurrency wallets and password managers. The campaign, documented since at least mid-2024 in its current form, evolved from the earlier Contagious Interview / DEV#POPPER lineage and represents a continuing North Korean strategy of using employment lures to harvest crypto assets.

Have evidence about Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)?
0
Accepted
1
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminatingWayback pending8/4/2026, 4:19:33 PM

    Cisco Talos July 2026 technical analysis of PylangGhost — the Python Windows RAT variant targeting Web3 professionals, a new capability not previously documented on the existing investigation page

    avoid-scout

Timeline(11 events)

2022-12-01

Contagious Interview campaign begins, targeting software developers via fake GitHub-hosted coding assessments. Attributed to Famous Chollima / Lazarus Group.

Sekoia Research / Palo Alto Networks

2023-11-01

Palo Alto Networks publicly documents the Contagious Interview campaign for the first time.

The Hacker News

2024-06-01

Campaign evolves; GolangGhost backdoor and FrostyFerret macOS stealer first observed in ongoing fake interview operations.

Cisco Talos

2025-02-21

Lazarus Group (TraderTraitor) steals approximately $1.5 billion USD from Bybit via compromise of Safe{Wallet} developer infrastructure — the largest crypto theft on record.

FBI IC3 PSA

2025-02-26

FBI IC3 releases public service announcement attributing the Bybit theft to North Korea's Lazarus Group (TraderTraitor) and publishing 52 associated Ethereum wallet addresses.

FBI Internet Crime Complaint Center

2025-03-21

Sekoia distributes private FLINT report codenaming the evolved campaign ClickFake Interview, documenting GolangGhost, FrostyFerret, and the shift to ClickFix social engineering and CeFi targeting.

Sekoia

2025-04-01

Sekoia publicly releases ClickFake Interview research; The Hacker News and Infosecurity Magazine cover findings. Campaign linked to 40+ companion domains registered in April 2025.

The Hacker News

2025-05-01

Cisco Talos identifies PylangGhost, a Python-based Windows RAT functionally equivalent to GolangGhost, marking a new malware family exclusive to Famous Chollima in the ClickFake campaign.

Cisco Talos

2026-03-11

Microsoft Security Blog publishes detailed analysis of the Contagious Interview malware delivery campaign including BeaverTail, InvisibleFerret, and related tooling.

Microsoft Security Blog

2026-07-20

SOCRadar Threat Research Unit publishes updated analysis of the ClickFake Interview campaign documenting PylangGhost and GolangGhost targeting Web3 professionals, with new infrastructure observations including Nuitka-compiled variants.

SOCRadar

2026-07-22

GBHackers and Infosecurity Magazine publish coverage of the active ClickFake Interview campaign deploying PylangGhost and GolangGhost RATs.

GBHackers / Infosecurity Magazine
Provenance & Audit Trail
17 Wayback Archives

Decision Log

  • #1publish⛓ pending8/4/2026, 12:17:37 PM
    hash: 2Qzdbuu1pjwttU1riRHYwc24Jp87eKMV3eTGhRMrLitB

17 of 18 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/4/2026, 12:17:27 PM

last updated: 8/4/2026, 4:11:10 PM

avoid.net — verified advice for a post-truth world