"one in three employees admit to using company tech to apply for jobs, interview, or do work for other companies," the SOCRadar Threat Research Unit noted — a statistic it tied directly to a newly uncovered recruitment trick that can hand attackers keys to corporate coffers.
Famous Chollima (also known as Wagemole) and the 'ClickFake Interview'
Researchers at SOCRadar say they have uncovered a sophisticated social engineering campaign attributed to the North Korean-aligned hacking group Famous Chollima, also known as Wagemole. The operation targets Web3 and cryptocurrency professionals by posing as legitimate recruiters or fictitious companies on mainstream professional networks and communication platforms, including LinkedIn, Telegram, Discord and direct email. Rather than broad phishing, the team observed a shift to highly personalized recruitment scams designed to exploit the mobility and market hunger of crypto talent.
How the ClickFix lure and interactive portals work
SOCRadar describes the central deception as a staged assessment hosted on attacker-controlled, highly interactive web portals. Targets who accept an interview are directed to these portals, which use real-time monitoring, psychometrics, strict gating, tailored interview questions, countdown timers and automated warnings when users attempt to switch tabs. The portals create psychological pressure and deter on-the-fly research.
The decisive trick — branded in the report as ClickFix — intentionally simulates an error during the assessment, claiming the page cannot access the candidate's camera or microphone. To 'fix' the problem the page instructs the user to copy and paste a diagnostic command into their system terminal. SOCRadar says that by exploiting the user's desire to perform under time pressure, attackers bypass normal security caution and system warnings.
PylangGhost for Windows and GolangGhost for macOS
The STRU report lays out two distinct infection chains tied to the diagnostic command.
- Windows: Executing the command fetches a ZIP archive via native utilities such as PowerShell or curl; a Visual Basic Script silently unpacks a Python runtime, which runs an execution wrapper that loads PylangGhost, a customized remote access trojan (RAT). The actors compile Python payloads into native dynamic link libraries using Nuitka to evade signature-based detection.
- macOS: The command fetches and executes GolangGhost, a RAT written in Go. On Apple devices the infection frequently installs the primary payload alongside a credential-harvesting helper built with SwiftUI intended to trick users into providing administrative passwords.
Modular stealers and targeted cryptocurrency tooling
Both PylangGhost and GolangGhost are modular, composed of six interconnected components: a main orchestrator, a configuration holder, an archive helper, a command launcher, a command-and-control communications module, and a specialized data stealer. That modular design enables on-demand capability loading, persistence, and remote command execution.
The integrated stealer targets more than 80 browser extensions. SOCRadar lists specific targets including cryptocurrency wallet extensions — MetaMask, Phantom and TronLink — and commercial password managers such as NordPass. The malware is programmed to harvest session data, saved credentials and private keys. SOCRadar warns that because many Web3 professionals manage corporate infrastructure through browser-based tools, a single successful intrusion can grant attackers access to millions of dollars in digital assets.
Infrastructure choices and anti-analysis measures
The report says Famous Chollima favors rapid, low-cost infrastructure over durable operations: the actors register domains using budget-friendly registrars such as Hostinger and NameCheap, spinning up new assessment portals quickly as defenders blacklist old ones. They also use precise targeting controls — blocking mobile devices and validating individual invitation links — specifically to prevent automated malware sandboxes and security analysts from studying payload delivery.
What this means for Web3 professionals, security teams, and employers
- Web3 professionals: SOCRadar's findings show a high-risk scenario for individuals who respond to recruiter outreach on platforms named in the report; the ClickFix prompt is engineered to look helpful while delivering remote access malware.
- Security teams and enterprises: Because the campaign seeks indirect access to pivot toward company funds, organizations face exposure when employees use corporate devices during job hunting. The STRU report explicitly links the campaign's danger to the reported behavior that one in three employees use company tech for job-related activity.
- Incident response and defenders: The rapid churn of attacker-controlled assessment portals and anti-sandbox controls mean defenders must combine URL/blocklist agility with behavioral detection that looks for runtime unpacking, Nuitka-compiled modules and unusual credential-exfiltration patterns tied to wallet extensions and password managers.
SOCRadar's July 20 report frames this campaign as a deliberate, tailored evolution of recruitment fraud into an efficient commodity for financial theft. The combination of social engineering that wins trust, interactive portals that suppress scrutiny, dual-platform RATs and a broad extension-stealing capability makes the campaign consequential for both individual Web3 professionals and the companies whose assets they touch.




