North Korean Hackers Target Web3 Experts: Unveiling the ClickFake Campaign (2026)

In the world of cybersecurity, where threats are constantly evolving, the latest discovery by researchers at SOCRadar Threat Research Unit (STRU) has shed light on a sophisticated North Korean-aligned hacking group, Famous Chollima, and their 'ClickFake' campaign targeting Web3 and cryptocurrency professionals. This operation is a prime example of how cybercriminals are adapting to the dynamic landscape of technology, leveraging personalized recruitment scams and advanced malware to exploit the high mobility of tech talent in the cryptocurrency market.

What makes this campaign particularly intriguing is the group's shift from broad phishing blasts to highly personalized recruitment scams. By manufacturing elaborate pretexts and establishing a high degree of trust with their targets, Famous Chollima sets the stage for a decisive blow. The attack begins on mainstream professional networks and communication platforms, including LinkedIn, Telegram, Discord, and direct email, enticing candidates with lucrative salary packages and prestigious career advancements.

One of the key techniques employed in this campaign is the ClickFix lure. While the candidate is performing the assessment, the platform artificially triggers a simulated error, claiming that the system cannot access the user's camera or microphone. To resolve the issue, the page displays a helpful prompt instructing the candidate to copy and paste a diagnostic command into their system terminal. This technique, combined with the use of real-time monitoring and psychometrics, creates a highly interactive and authentic experience for the candidate, successfully deterring them from researching the suspicious behavior of the page.

The malware suite used in this campaign, PylangGhost and GolangGhost, is built on a highly modular architecture consisting of six interconnected parts. These components include a main orchestrator, a dedicated configuration holder, an archive helper, a command launcher, a command-and-control (C2) communications module, and a specialized data stealer. By dividing functionality across these distinct modules, the malware can seamlessly execute commands, manage persistence, and dynamically load new capabilities based on instructions received from the attacker's server.

The primary objective of this dual-headed malware suite is financial gain through asset theft. The integrated stealer module targets more than 80 distinct browser extensions, harvesting session data, saved credentials, and private keys from widely used cryptocurrency wallets such as MetaMask, Phantom, and TronLink, as well as commercial password managers like NordPass. Because many Web3 professionals manage corporate infrastructure using browser-based tools, a single successful intrusion can grant attackers access to millions of dollars in digital assets.

What makes this campaign particularly alarming is the group's ability to rapidly register domains using budget-friendly registrars like Hostinger and NameCheap. Rather than focusing on long-term infrastructure resilience, they prioritize speed and sheer volume, spinning up new assessment portals as quickly as defenders can blacklist the old ones. They also implement precise targeting controls, such as blocking mobile devices and validating individual invitation links, to prevent automated malware sandboxes and security analysts from studying their payload delivery mechanisms.

In conclusion, the 'ClickFake' campaign by Famous Chollima is a stark reminder of the evolving nature of cyber threats and the need for constant vigilance. As technology advances, so do the techniques of cybercriminals, making it crucial for organizations and individuals to stay informed and proactive in their defense against these threats. From personalized recruitment scams to advanced malware, the campaign highlights the importance of staying alert and implementing robust security measures to protect against these sophisticated attacks.

North Korean Hackers Target Web3 Experts: Unveiling the ClickFake Campaign (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Foster Heidenreich CPA

Last Updated:

Views: 6441

Rating: 4.6 / 5 (56 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Foster Heidenreich CPA

Birthday: 1995-01-14

Address: 55021 Usha Garden, North Larisa, DE 19209

Phone: +6812240846623

Job: Corporate Healthcare Strategist

Hobby: Singing, Listening to music, Rafting, LARPing, Gardening, Quilting, Rappelling

Introduction: My name is Foster Heidenreich CPA, I am a delightful, quaint, glorious, quaint, faithful, enchanting, fine person who loves writing and wants to share my knowledge and understanding with you.