A new malware campaign is targeting cryptocurrency and Web3 professionals through fake job interviews.
The operation delivers GolangGhost, a remote access trojan that can steal browser credentials, collect wallet data, and give attackers control of infected macOS systems.
The attackers pose as recruiters, offer attractive roles, and direct targets to fake online skill assessments.
At the final video-recording stage, the site displays a false camera error and persuades victims to copy and paste a supposed fix into their Mac Terminal.
SOCRadar said in a report shared with Cyber Security News (CSN) that the campaign is linked to the North Korean-aligned Famous Chollima group, also tracked as Wagemole.
The campaign delivers PylangGhost to Windows users and GolangGhost to macOS users through the same deceptive recruitment process.
The risk extends beyond a single compromised device. People working in crypto, investment, legal, advisory, and business roles may hold direct access to wallets, company accounts, or sensitive information that attackers can use to steal digital assets or move deeper into an organization.
Similar fake recruiter malware campaigns have repeatedly targeted the crypto sector.
GolangGhost Steals Chrome Secrets
On macOS, the copied command starts a Bash script that creates a hidden working directory, downloads a fake Intel driver archive, and retrieves the Go compiler needed to run GolangGhost.
The script also establishes persistence through a Launch Agent, allowing the malware to restart after a reboot.
GolangGhost can use the macOS Keychain command-line utility to retrieve Chrome’s stored master password. It then applies that secret to decrypt Chrome’s local database, exposing saved browser credentials and cookies that may grant access to online services.
.webp)
This mirrors the danger seen in macOS credential stealing malware, which has also targeted browser data and wallet information.
The malware also searches for browser extension data associated with cryptocurrency wallets and password managers.
Its targets include MetaMask and several other wallet extensions, enabling attackers to collect extension settings and related data from Chrome profiles.
More concerningly, GolangGhost can alter Chrome’s Secure Preferences file after forcing the browser to close.
The malware injects broad permissions, including access to active tabs, clipboard writing, web requests, and expanded storage, then assigns them to the MetaMask extension. That change could let attackers abuse the wallet extension’s trusted browser position.
Fake Interviews Drive Infection
The ClickFake interview pages are designed to make victims act quickly. They collect personal information, fingerprint the visitor’s browser and device, block mobile users, show timed assessment questions, and display warnings when candidates switch browser tabs.
At the final step, the attackers present a realistic camera or microphone troubleshooting prompt.
The page replaces the harmless command copied by the victim with a malicious one, while displaying the expected text in Terminal to reduce suspicion.
Recent ClickFix malware campaigns show how this approach turns a victim’s own action into initial access.
.webp)
The campaign also launches a fake macOS application that requests administrator credentials under the guise of an update.
Those credentials are sent to attacker-controlled infrastructure, adding another path to account takeover and device control.
Organizations should train staff, especially non-technical employees, to treat unsolicited interview requests and copy-and-paste troubleshooting steps as warning signs.
Security teams should prevent personal job hunting on corporate devices, review unexpected Launch Agents and browser-preference changes, and use detections that inspect suspicious compiled modules and dynamic libraries.
The threat also reinforces why teams should avoid untrusted recruitment software packages during hiring conversations.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | paxos-apply.com | Fake recruitment infrastructure |
| Domain | cameradriverupdates.com | Fake recruitment infrastructure |
| Domain | highmatch.pro | Fake recruitment infrastructure |
| Domain | highmatch.cloud | Fake recruitment infrastructure |
| Domain | tailora.org | Fake recruitment infrastructure |
| Domain | breezyhr.us | Typosquatted recruitment platform |
| Domain | rolevia.us | Fake recruitment infrastructure |
| Domain | medincahub.com | Fake recruitment infrastructure |
| Domain | cincopa.org | Fake recruitment infrastructure |
| Domain | knockri.us | Fake recruitment infrastructure |
| Domain | spiralboard.com | Fake recruitment infrastructure |
| Domain | kaltura.studio | Fake recruitment infrastructure |
| Domain | paxos-video-interviews.com | Fake recruitment infrastructure |
| Domain | videohirepro.com | Fake recruitment infrastructure |
| Domain | evaluateproficiency.com | Fake recruitment infrastructure |
| Domain | paxos-video-recording.com | Fake recruitment infrastructure |
| Domain | video-hiring.com | Fake recruitment infrastructure |
| Domain | vervoe.app | Fake recruitment infrastructure |
| Domain | canditech.us | Fake recruitment infrastructure |
| Domain | hirvexo.com | Fake recruitment infrastructure |
| Domain | hiring-you.com | Fake recruitment infrastructure |
| Domain | gumlet.us | Fake recruitment infrastructure |
| Domain | survicate.us | Fake recruitment infrastructure |
| Domain | ziggeo.tech | Campaign infrastructure |
| Domain | insighboard.com | Campaign infrastructure |
| Domain | zavnia.us | Campaign infrastructure |
| Domain | mettl.us | Campaign infrastructure |
| Domain | tecmlny.com | Campaign infrastructure |
| Domain | zynoracreative.com | Campaign infrastructure |
| Domain | workbright.us | Campaign infrastructure |
| Domain | me-c0h.pages.dev | Campaign infrastructure |
| Domain | evaluza.com | Campaign infrastructure |
| Domain | evaluino.com | Campaign infrastructure |
| Domain | nvidiadriver.net | Payload hosting domain |
| IP Address | 95.216.92.207 | Command-and-control infrastructure |
| URL | hxxp://nvidiadriver.net/verv1432/drivers/intel-driver-xd7d.zip | GolangGhost payload archive |
| URL | hxxp://95.216.92.207:8080 | Command-and-control endpoint |
| URL | hxxp://95.216.92.207:8080/gettext | Credential exfiltration endpoint |
| SHA-256 | 96ce1b7f2026dfd3dbb806c246c27ce3b105a9e78482956fae42258980425cd0 | ClickFix-related file |
| SHA-256 | b9a8ae1e6d2c875e21c77f3b9255ca0b3b0b3e0addbb2c3c865e5b95eb734d22 | winPatch-related file |
| SHA-256 | 466170079e4b9e26e41a25ca45ff8a7f6cc9b3e9e7f2beda99f3dd042e72c1b | update.vbs |
| SHA-256 | 164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3 | audiodriver module |
| SHA-256 | df6669bd504ce6b0e303be7ee47f2ebbc062989c88c41f0a3f436044a24869798 | config module |
| SHA-256 | 50ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdf | api module |
| SHA-256 | 3c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2 | command module |
| SHA-256 | 282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990 | util module |
| SHA-256 | 17832aa629524ef6e8d8d6e9b6b902a8d324b559e3c36dbd0e221ab1690be871 | auto module |
| SHA-256 | 0ca62fe52a895bad73a14f1a455e1bead18b8c256749d727c2678924298f7ee8 | macPatch.sh |
| SHA-256 | 617779f417c1850c08ed55ba49e2317aed0e1e911fca8bf8f348189ee4ebdb97 | drivfixer.sh |
| SHA-256 | ee59683f2ab7ba05da5443a153aee221af08ba884461f74dd8b114c0d10febbeb | main.go |
| SHA-256 | 337dfb06e08ac8ceb47728b50de006ef82f5e61fa245494210a362bab15859f | coreiter.go |
| SHA-256 | f53567c1a8885925393a1771cded2ff2c8ef4ab38da1bf97d36f153f81f72e80 | instancecheck.go |
| SHA-256 | 95983760b571631e1da0f52f51c7a274f2a34e44de5e3d10cadcf8b30edf959c | commandstackcmd.go |
| SHA-256 | 6110ea43d734a296a8e5676192c56cdbdad11c94c3eecda7b55a4672e16d35d4 | configconstants.go |
| SHA-256 | 6295839b6c9414d9cd0f2402f4cd72e219f75cc4dfac720cec297fddc4f20ff2 | utilcompress.go |
| SHA-256 | 6850cdb307fc72e052719939efbf705beb8d50775b260a18aff0adba536d7dea | transporthtxp.go |
| SHA-256 | 4387b79045065622e7fd643b65d85998f092c4b32e53633d36bd7ef46181cbe2 | autobasic.go |
| SHA-256 | 0827606854b6fd7fa73f13f2e453d9720d79c63e89308cfed0b577a16d84bccd | autchromechangepref.go |
| SHA-256 | 756846dfa3c258807b6962bb66373a543aa6b4ba0a35ffc4a526e4b07a84d9dc | autochromecookiedarwin.go |
| SHA-256 | 319adf187bce5bd85dbb5b06f99ce78baa807af590feaed44a6f932d4d5b9003 | autochromecookieother.go |
| SHA-256 | d1934fdd449b6e8124b632f680cbe6893ac39e740559b1882641204040c70a99 | autochromecookiewin.go |
| SHA-256 | 47a3ce02388c845e5f1ed8f4d3673e2c99a643b88d3f2fa06cbfe0c78502264d | autochromegather.go |
| SHA-256 | 1cee591c63d7fd8ee963abb29789c3ee41eb42cc77470964a00ea15be4b51341 | CodeFixerNow.app |
| SHA-256 | 9e465904503815c27397e082fd5ca8eb30d99d8d256c6a0949696d1830c8bb53 | CodeFixerNow.debug.dylib |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposuremalware to businesses an

