Recent information from Cisco Talos reveals new attack methods by a North Korean-affiliated hacking group targeting job seekers in the crypto industry.
Attack Methods on Job Seekers
Hackers create fake job sites impersonating well-known companies, such as Coinbase and Uniswap. Victims go through multiple steps, including contact from fake recruiters who redirect them to skill-testing sites.
Technical Details of New Malware
The new malware, called PylangGhost, is a remote access trojan (RAT) that enables hackers to control infected systems and steal data from over 80 browser extensions, including cryptocurrency wallets.
Previous Incidents Targeting Crypto Developers
This is not the first instance of hackers affiliated with North Korea using fake job offers. In April, hackers linked to a $1.4 billion heist also targeted crypto developers with fake recruitment tests.
Attacks targeting crypto job seekers using malware are becoming increasingly sophisticated. Users should exercise caution when engaging with job offers in the crypto industry.