PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware Activity
Summary
Hide ▲
Show ▼
The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 and cryptocurrency professionals at risk of credential theft and remote compromise. The payloads also bundle credential-harvesting helpers and extension-stealing modules aimed at browser wallets and password managers.
Related Happenings
Famous Chollima ClickFake Interview recruitment scam campaign
Campaign
H score34
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
How related:
A new sophisticated social engineering operation targeting Web3 and cryptocurrency professionals has been identified by researchers at SOCRadar.
About this happening:
A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...
Famous Chollima ClickFake Interview recruitment scam campaign
CampaignHow related: A new sophisticated social engineering operation targeting Web3 and cryptocurrency professionals has been identified by researchers at SOCRadar.
About this happening: A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
BusySnake Stealer Windows information-theft activity
Malware Activity
H score30
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The BusySnake Stealer malware is being used against Windows systems to steal browser cookies, passwords, documents, screenshots, wallet files, and Telegram data, increasin...
BusySnake Stealer Windows information-theft activity
Malware ActivityAbout this happening: The BusySnake Stealer malware is being used against Windows systems to steal browser cookies, passwords, documents, screenshots, wallet files, and Telegram data, increasin...
MacOS ClickFix Terminal-delivered DMG campaign
Campaign
H score37
First: 23.06.2026 21:30
Last: 23.06.2026 21:30
Sources 1
About this happening:
A macOS ClickFix campaign is using fake CAPTCHA pages and Terminal commands to quietly download and launch malicious DMG files, putting Mac devices at risk of...
MacOS ClickFix Terminal-delivered DMG campaign
CampaignAbout this happening: A macOS ClickFix campaign is using fake CAPTCHA pages and Terminal commands to quietly download and launch malicious DMG files, putting Mac devices at risk of...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Timeline
-
21.07.2026 12:30 2 articles · 5h ago
SOCRadar identifies a ClickFake Interview campaign targeting Web3 professionals
Initial DisclosureSOCRadar Threat Research Unit identified a North Korean-aligned social-engineering campaign by Famous Chollima, also known as Wagemole, that targets Web3 and cryptocurrency professionals with fake job interviews, malicious assessment portals, and ClickFix lures designed to push victims into running terminal commands on their devices. The Windows chain uses PowerShell or curl, a ZIP archive, Visual Basic Script, and a Python runtime to load PylangGhost, while the macOS path fetches and executes GolangGhost and may install a SwiftUI credential-harvesting helper to steal administrative passwords and browser-based crypto data.
Show sources
- Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros — www.infosecurity-magazine.com — 21.07.2026 12:30
- Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros — www.infosecurity-magazine.com — 21.07.2026 12:30