Cisco Talos has reported on a new malware called PylangGhost, used by the North Korean hacking group Famous Chollima to target users seeking jobs in the crypto industry.
PylangGhost Overview
PylangGhost is a new Python-based malware similar to the previously documented GolangGhost RAT. It is exclusively used by North Korea-affiliated cyber threat actors and targets both Windows and MacOS systems, with most victims located in India.
Hacker Tactics
The Famous Chollima group lures victims in through fake job advertisements using social engineering. They create counterfeit sites impersonating well-known cryptocurrency exchanges like Coinbase and Robinhood, collecting personal data under the guise of skill-testing.
Previous Actions of Famous Chollima
Famous Chollima, nicknamed 'Wagemole,' has repeatedly attempted to steal passwords and crypto wallet data through fake job offers. Similar methods have been employed by another North Korean group, Lazarus Group.
The discovery of PylangGhost highlights ongoing targeted attacks by North Korean groups attracting victims through fake job offers. This raises concerns about the need for greater awareness in cybersecurity.