North Korean Hackers Target Web3 Experts: Unveiling the ClickFake Campaign (2026)

In the world of cybersecurity, where threats are constantly evolving, the latest discovery by researchers at SOCRadar Threat Research Unit (STRU) has shed light on a sophisticated North Korean-aligned hacking group, Famous Chollima, and their 'ClickFake' campaign targeting Web3 and cryptocurrency professionals. This operation is a prime example of how cybercriminals are adapting to the dynamic landscape of technology, leveraging personalized recruitment scams and advanced malware to exploit the high mobility of tech talent in the cryptocurrency market.

What makes this campaign particularly intriguing is the group's shift from broad phishing blasts to highly personalized recruitment scams. By manufacturing elaborate pretexts and establishing a high degree of trust with their targets, Famous Chollima sets the stage for a decisive blow. The attack begins on mainstream professional networks and communication platforms, including LinkedIn, Telegram, Discord, and direct email, enticing candidates with lucrative salary packages and prestigious career advancements.

One of the key techniques employed in this campaign is the ClickFix lure. While the candidate is performing the assessment, the platform artificially triggers a simulated error, claiming that the system cannot access the user's camera or microphone. To resolve the issue, the page displays a helpful prompt instructing the candidate to copy and paste a diagnostic command into their system terminal. This technique, combined with the use of real-time monitoring and psychometrics, creates a highly interactive and authentic experience for the candidate, successfully deterring them from researching the suspicious behavior of the page.

The malware suite used in this campaign, PylangGhost and GolangGhost, is built on a highly modular architecture consisting of six interconnected parts. These components include a main orchestrator, a dedicated configuration holder, an archive helper, a command launcher, a command-and-control (C2) communications module, and a specialized data stealer. By dividing functionality across these distinct modules, the malware can seamlessly execute commands, manage persistence, and dynamically load new capabilities based on instructions received from the attacker's server.

The primary objective of this dual-headed malware suite is financial gain through asset theft. The integrated stealer module targets more than 80 distinct browser extensions, harvesting session data, saved credentials, and private keys from widely used cryptocurrency wallets such as MetaMask, Phantom, and TronLink, as well as commercial password managers like NordPass. Because many Web3 professionals manage corporate infrastructure using browser-based tools, a single successful intrusion can grant attackers access to millions of dollars in digital assets.

What makes this campaign particularly alarming is the group's ability to rapidly register domains using budget-friendly registrars like Hostinger and NameCheap. Rather than focusing on long-term infrastructure resilience, they prioritize speed and sheer volume, spinning up new assessment portals as quickly as defenders can blacklist the old ones. They also implement precise targeting controls, such as blocking mobile devices and validating individual invitation links, to prevent automated malware sandboxes and security analysts from studying their payload delivery mechanisms.

In conclusion, the 'ClickFake' campaign by Famous Chollima is a stark reminder of the evolving nature of cyber threats and the need for constant vigilance. As technology advances, so do the techniques of cybercriminals, making it crucial for organizations and individuals to stay informed and proactive in their defense against these threats. From personalized recruitment scams to advanced malware, the campaign highlights the importance of staying alert and implementing robust security measures to protect against these sophisticated attacks.

North Korean Hackers Target Web3 Experts: Unveiling the ClickFake Campaign (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Aron Pacocha

Last Updated:

Views: 5780

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Aron Pacocha

Birthday: 1999-08-12

Address: 3808 Moen Corner, Gorczanyport, FL 67364-2074

Phone: +393457723392

Job: Retail Consultant

Hobby: Jewelry making, Cooking, Gaming, Reading, Juggling, Cabaret, Origami

Introduction: My name is Aron Pacocha, I am a happy, tasty, innocent, proud, talented, courageous, magnificent person who loves writing and wants to share my knowledge and understanding with you.