Find notable cyber news and cases, enriched with sources, timelines, and signals.

PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 and cryptocurrency professionals at risk of credential theft and remote compromise. The payloads also bundle credential-harvesting helpers and extension-stealing modules aimed at browser wallets and password managers.

Related Happenings

Famous Chollima ClickFake Interview recruitment scam campaign

Campaign
H score34 First: 21.07.2026 12:30 Last: 21.07.2026 12:30 Sources 1

How related: A new sophisticated social engineering operation targeting Web3 and cryptocurrency professionals has been identified by researchers at SOCRadar.

About this happening: A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

BusySnake Stealer Windows information-theft activity

Malware Activity
H score30 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The BusySnake Stealer malware is being used against Windows systems to steal browser cookies, passwords, documents, screenshots, wallet files, and Telegram data, increasin...

MacOS ClickFix Terminal-delivered DMG campaign

Campaign
H score37 First: 23.06.2026 21:30 Last: 23.06.2026 21:30 Sources 1

About this happening: A macOS ClickFix campaign is using fake CAPTCHA pages and Terminal commands to quietly download and launch malicious DMG files, putting Mac devices at risk of...

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
H score13 First: 18.06.2026 18:00 Last: 18.06.2026 18:00 Sources 1

About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...

Timeline

  1. 21.07.2026 12:30 2 articles · 5h ago

    SOCRadar identifies a ClickFake Interview campaign targeting Web3 professionals

    Initial Disclosure

    SOCRadar Threat Research Unit identified a North Korean-aligned social-engineering campaign by Famous Chollima, also known as Wagemole, that targets Web3 and cryptocurrency professionals with fake job interviews, malicious assessment portals, and ClickFix lures designed to push victims into running terminal commands on their devices. The Windows chain uses PowerShell or curl, a ZIP archive, Visual Basic Script, and a Python runtime to load PylangGhost, while the macOS path fetches and executes GolangGhost and may install a SwiftUI credential-harvesting helper to steal administrative passwords and browser-based crypto data.

    Show sources