CyberSecurityNews

GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions


A new malware campaign is targeting cryptocurrency and Web3 professionals through fake job interviews.

The operation delivers GolangGhost, a remote access trojan that can steal browser credentials, collect wallet data, and give attackers control of infected macOS systems.

The attackers pose as recruiters, offer attractive roles, and direct targets to fake online skill assessments.

At the final video-recording stage, the site displays a false camera error and persuades victims to copy and paste a supposed fix into their Mac Terminal.

SOCRadar said in a report shared with Cyber Security News (CSN) that the campaign is linked to the North Korean-aligned Famous Chollima group, also tracked as Wagemole.

The campaign delivers PylangGhost to Windows users and GolangGhost to macOS users through the same deceptive recruitment process.

Financially motivated DPRK campaigns (Source – SOCRadar)

The risk extends beyond a single compromised device. People working in crypto, investment, legal, advisory, and business roles may hold direct access to wallets, company accounts, or sensitive information that attackers can use to steal digital assets or move deeper into an organization.

Similar fake recruiter malware campaigns have repeatedly targeted the crypto sector.

GolangGhost Steals Chrome Secrets

On macOS, the copied command starts a Bash script that creates a hidden working directory, downloads a fake Intel driver archive, and retrieves the Go compiler needed to run GolangGhost.

The script also establishes persistence through a Launch Agent, allowing the malware to restart after a reboot.

GolangGhost can use the macOS Keychain command-line utility to retrieve Chrome’s stored master password. It then applies that secret to decrypt Chrome’s local database, exposing saved browser credentials and cookies that may grant access to online services.

ClickFake Interview attack chain (Source - SOCRadar)
ClickFake Interview attack chain (Source – SOCRadar)

This mirrors the danger seen in macOS credential stealing malware, which has also targeted browser data and wallet information.

The malware also searches for browser extension data associated with cryptocurrency wallets and password managers.

Its targets include MetaMask and several other wallet extensions, enabling attackers to collect extension settings and related data from Chrome profiles.

More concerningly, GolangGhost can alter Chrome’s Secure Preferences file after forcing the browser to close.

The malware injects broad permissions, including access to active tabs, clipboard writing, web requests, and expanded storage, then assigns them to the MetaMask extension. That change could let attackers abuse the wallet extension’s trusted browser position.

Fake Interviews Drive Infection

The ClickFake interview pages are designed to make victims act quickly. They collect personal information, fingerprint the visitor’s browser and device, block mobile users, show timed assessment questions, and display warnings when candidates switch browser tabs.

At the final step, the attackers present a realistic camera or microphone troubleshooting prompt.

The page replaces the harmless command copied by the victim with a malicious one, while displaying the expected text in Terminal to reduce suspicion.

Recent ClickFix malware campaigns show how this approach turns a victim’s own action into initial access.

Sample ClickFix instruction from the ClickFake Campaign (Source - SOCRadar)
Sample ClickFix instruction from the ClickFake Campaign (Source – SOCRadar)

The campaign also launches a fake macOS application that requests administrator credentials under the guise of an update.

Those credentials are sent to attacker-controlled infrastructure, adding another path to account takeover and device control.

Organizations should train staff, especially non-technical employees, to treat unsolicited interview requests and copy-and-paste troubleshooting steps as warning signs.

Security teams should prevent personal job hunting on corporate devices, review unexpected Launch Agents and browser-preference changes, and use detections that inspect suspicious compiled modules and dynamic libraries.

The threat also reinforces why teams should avoid untrusted recruitment software packages during hiring conversations.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Domainpaxos-apply.comFake recruitment infrastructure
Domaincameradriverupdates.comFake recruitment infrastructure
Domainhighmatch.proFake recruitment infrastructure
Domainhighmatch.cloudFake recruitment infrastructure
Domaintailora.orgFake recruitment infrastructure
Domainbreezyhr.usTyposquatted recruitment platform
Domainrolevia.usFake recruitment infrastructure
Domainmedincahub.comFake recruitment infrastructure
Domaincincopa.orgFake recruitment infrastructure
Domainknockri.usFake recruitment infrastructure
Domainspiralboard.comFake recruitment infrastructure
Domainkaltura.studioFake recruitment infrastructure
Domainpaxos-video-interviews.comFake recruitment infrastructure
Domainvideohirepro.comFake recruitment infrastructure
Domainevaluateproficiency.comFake recruitment infrastructure
Domainpaxos-video-recording.comFake recruitment infrastructure
Domainvideo-hiring.comFake recruitment infrastructure
Domainvervoe.appFake recruitment infrastructure
Domaincanditech.usFake recruitment infrastructure
Domainhirvexo.comFake recruitment infrastructure
Domainhiring-you.comFake recruitment infrastructure
Domaingumlet.usFake recruitment infrastructure
Domainsurvicate.usFake recruitment infrastructure
Domainziggeo.techCampaign infrastructure
Domaininsighboard.comCampaign infrastructure
Domainzavnia.usCampaign infrastructure
Domainmettl.usCampaign infrastructure
Domaintecmlny.comCampaign infrastructure
Domainzynoracreative.comCampaign infrastructure
Domainworkbright.usCampaign infrastructure
Domainme-c0h.pages.devCampaign infrastructure
Domainevaluza.comCampaign infrastructure
Domainevaluino.comCampaign infrastructure
Domainnvidiadriver.netPayload hosting domain
IP Address95.216.92.207Command-and-control infrastructure
URLhxxp://nvidiadriver.net/verv1432/drivers/intel-driver-xd7d.zipGolangGhost payload archive
URLhxxp://95.216.92.207:8080Command-and-control endpoint
URLhxxp://95.216.92.207:8080/gettextCredential exfiltration endpoint
SHA-25696ce1b7f2026dfd3dbb806c246c27ce3b105a9e78482956fae42258980425cd0ClickFix-related file
SHA-256b9a8ae1e6d2c875e21c77f3b9255ca0b3b0b3e0addbb2c3c865e5b95eb734d22winPatch-related file
SHA-256466170079e4b9e26e41a25ca45ff8a7f6cc9b3e9e7f2beda99f3dd042e72c1bupdate.vbs
SHA-256164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3audiodriver module
SHA-256df6669bd504ce6b0e303be7ee47f2ebbc062989c88c41f0a3f436044a24869798config module
SHA-25650ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdfapi module
SHA-2563c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2command module
SHA-256282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990util module
SHA-25617832aa629524ef6e8d8d6e9b6b902a8d324b559e3c36dbd0e221ab1690be871auto module
SHA-2560ca62fe52a895bad73a14f1a455e1bead18b8c256749d727c2678924298f7ee8macPatch.sh
SHA-256617779f417c1850c08ed55ba49e2317aed0e1e911fca8bf8f348189ee4ebdb97drivfixer.sh
SHA-256ee59683f2ab7ba05da5443a153aee221af08ba884461f74dd8b114c0d10febbebmain.go
SHA-256337dfb06e08ac8ceb47728b50de006ef82f5e61fa245494210a362bab15859fcoreiter.go
SHA-256f53567c1a8885925393a1771cded2ff2c8ef4ab38da1bf97d36f153f81f72e80instancecheck.go
SHA-25695983760b571631e1da0f52f51c7a274f2a34e44de5e3d10cadcf8b30edf959ccommandstackcmd.go
SHA-2566110ea43d734a296a8e5676192c56cdbdad11c94c3eecda7b55a4672e16d35d4configconstants.go
SHA-2566295839b6c9414d9cd0f2402f4cd72e219f75cc4dfac720cec297fddc4f20ff2utilcompress.go
SHA-2566850cdb307fc72e052719939efbf705beb8d50775b260a18aff0adba536d7deatransporthtxp.go
SHA-2564387b79045065622e7fd643b65d85998f092c4b32e53633d36bd7ef46181cbe2autobasic.go
SHA-2560827606854b6fd7fa73f13f2e453d9720d79c63e89308cfed0b577a16d84bccdautchromechangepref.go
SHA-256756846dfa3c258807b6962bb66373a543aa6b4ba0a35ffc4a526e4b07a84d9dcautochromecookiedarwin.go
SHA-256319adf187bce5bd85dbb5b06f99ce78baa807af590feaed44a6f932d4d5b9003autochromecookieother.go
SHA-256d1934fdd449b6e8124b632f680cbe6893ac39e740559b1882641204040c70a99autochromecookiewin.go
SHA-25647a3ce02388c845e5f1ed8f4d3673e2c99a643b88d3f2fa06cbfe0c78502264dautochromegather.go
SHA-2561cee591c63d7fd8ee963abb29789c3ee41eb42cc77470964a00ea15be4b51341CodeFixerNow.app
SHA-2569e465904503815c27397e082fd5ca8eb30d99d8d256c6a0949696d1830c8bb53CodeFixerNow.debug.dylib

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposuremalware to businesses an



Source link