financetom
Technology
financetom
/
Technology
/
North Korean Hackers Are Targeting Top Crypto Firms With Malware Hidden in Job Applications
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
North Korean Hackers Are Targeting Top Crypto Firms With Malware Hidden in Job Applications
Jun 20, 2025 3:19 AM

A North Korean hacking group is targeting crypto workers with a Python-based malware disguised as part of a fake job application process, researchers at Cisco Talos said earlier this week.

Most victims appear to be based in India, according to open-source signals, and seem to be individuals with prior experience in blockchain and cryptocurrency startups.

While Cisco ( CSCO ) reports no evidence of internal compromise, the broader risk remains clear: That these efforts are trying to gain access to the companies these individuals might eventually join.

The malware, called PylangGhost, is a new variant of the previously documented GolangGhost remote access trojan (RAT), and shares most of the same features — just rewritten in Python to better target Windows systems.

Mac users continue to be affected by the Golang version, while Linux systems appear to be unaffected. The threat actor behind the campaign, known as Famous Chollima, has been active since mid-2024 and is believed to be a DPRK-aligned group.

Their latest attack vector is simple: impersonate top crypto firms like Coinbase, Robinhood, and Uniswap through highly polished fake career sites, and lure software engineers, marketers, and designers into completing staged “skill tests.”

Once a target fills in basic information and answers technical questions, they’re prompted to install fake video drivers by pasting a command into their terminal, which quietly downloads and launches the Python-based RAT.

The payload is hidden in a ZIP file that includes the renamed Python interpreter (nvidia.py), a Visual Basic script to unpack the archive, and six core modules responsible for persistence, system fingerprinting, file transfer, remote shell access, and browser data theft.

The RAT pulls login credentials, session cookies, and wallet data from over 80 extensions, including MetaMask, Phantom, TronLink, and 1Password.

The command set allows full remote control of infected machines, including file uploads, downloads, system recon, and launching a shell — all routed through RC4-encrypted HTTP packets.

RC4-encrypted HTTP packets are data sent over the internet that are scrambled using an outdated encryption method called RC4. Even though the connection itself isn’t secure (HTTP), the data inside is encrypted, but not very well, since RC4 is outdated and easily broken by today’s standards.

Despite being a rewrite, the structure and naming conventions of PylangGhost mirror those of GolangGhost almost exactly, suggesting both were likely authored by the same operator, Cisco ( CSCO ) said.

Read more: North Korean Hackers Targeting Crypto Developers With U.S. Shell Firms

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
OpenAI clinches deal with Kakao, talks with SoftBank and Samsung about Stargate
OpenAI clinches deal with Kakao, talks with SoftBank and Samsung about Stargate
Feb 4, 2025
SEOUL (Reuters) -OpenAI said on Tuesday it will develop artificial intelligence products for South Korea with chat app operator Kakao, unveiling a second major alliance with a high-profile Asian partner this week. OpenAI Chief Executive Sam Altman also separately sat down with the leaders of Samsung Electronics, SoftBank and Arm Holdings in Seoul. SoftBank chief Masayoshi Son told reporters the...
Electronic Arts Set To Report Q3 Earnings Amid Analyst Downgrade, FC Franchise Concerns, 16% Year-To-Date Stock Decline
Electronic Arts Set To Report Q3 Earnings Amid Analyst Downgrade, FC Franchise Concerns, 16% Year-To-Date Stock Decline
Feb 4, 2025
Electronic Arts Inc. ( EA ) is scheduled to report its third-quarter earnings after market close on Tuesday. Earnings Estimates: Analysts are expecting revenue of $2.3 billion, down from $2.37 billion in the prior period, according to Benzinga Pro data. The video game publisher enters the earnings report under increased scrutiny after BofA Securities downgraded the stock to Neutral from Buy...
Software firm Dassault Systemes unveils 2025 outlook
Software firm Dassault Systemes unveils 2025 outlook
Feb 3, 2025
(Reuters) - French software company Dassault Systemes on Tuesday forecast total revenue growth of between 6% and 8% for 2025, above the 5% rise seen last year, citing their competitive positioning. The group, which sells its software to automakers, plane makers and industrial companies, also expects diluted earnings per share of between 1.36 euros and 1.39 euros ($1.43) euros. ($1...
AT&T Leverages Nokia Cloud Platform To Modernize IMS Voice Core
AT&T Leverages Nokia Cloud Platform To Modernize IMS Voice Core
Feb 4, 2025
AT&T Inc. ( T ) is extending its multi-year partnership with Nokia Corporation to enhance its voice core network. This agreement will help AT&T ( T ) advance its goal of delivering secure, customer-centric networks with improved automation, enabling new services, faster deployments, and greater operational efficiency. AT&T ( T ) is upgrading its existing Nokia IMS Voice Core to support...
Copyright 2023-2025 - www.financetom.com All Rights Reserved