Famous Chollima ClickFake Interview recruitment scam campaign
Campaign
Summary
Hide ▲
Show ▼
A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote access trojans. The operation uses ClickFix-style lures to trick candidates into running terminal commands, turning the interview flow into a malware delivery chain. The approach raises immediate risk to personal devices, saved credentials, and digital assets handled by the targets.
Related Happenings
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware Activity
H score29
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
How related:
The malicious terminal command fetches and executes GolangGhost, a remote access trojan written in Go.
About this happening:
The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware ActivityHow related: The malicious terminal command fetches and executes GolangGhost, a remote access trojan written in Go.
About this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
GPPStorm Google Partners enrollment phishing campaign
Campaign
H score33
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
GPPStorm Google Partners enrollment phishing campaign
CampaignAbout this happening: GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware Activity
H score29
First: 01.04.2026 16:30
Last: 01.04.2026 16:30
Sources 1
About this happening:
The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware ActivityAbout this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Contagious Interview cryptocurrency social-engineering and malware-delivery campaign
Campaign
H score37
First: 23.03.2026 20:09
Last: 23.03.2026 20:09
Sources 1
About this happening:
A North Korean cluster behind Contagious Interview / WaterPlum is running a coordinated malware campaign against cryptocurrency professionals, increasing the risk...
Contagious Interview cryptocurrency social-engineering and malware-delivery campaign
CampaignAbout this happening: A North Korean cluster behind Contagious Interview / WaterPlum is running a coordinated malware campaign against cryptocurrency professionals, increasing the risk...
Timeline
-
21.07.2026 12:30 2 articles · 5h ago
Famous Chollima targets Web3 professionals with ClickFake Interview scam
Initial DisclosureSOCRadar identified a North Korean-aligned social-engineering campaign by Famous Chollima, also known as Wagemole, that targets Web3 and cryptocurrency professionals with fake job interviews, ClickFix lures, and malicious assessment portals. The delivery chain pushes candidates through recruiter outreach on LinkedIn, Telegram, Discord, and direct email, then uses platform prompts and terminal commands to deliver PylangGhost on Windows and GolangGhost on macOS.
Show sources
- Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros — www.infosecurity-magazine.com — 21.07.2026 12:30
- Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros — www.infosecurity-magazine.com — 21.07.2026 12:30