North Korea's Chollima Group Runs Sophisticated ClickFake Interview Campaign
North Korea's Chollima threat group has been running a sophisticated cyberespionage campaign dubbed ClickFake Interview, targeting cryptocurrency and Web3 professionals.
The operation uses fake job interviews to trick candidates into executing terminal commands that infect their devices with platform-specific Remote Access Trojans (RATs): PylangGhost on Windows and GolangGhost on macOS.
According to SOCRadar Threat Research, the threat actor has industrialized fake recruitment workflows to establish initial access for financial theft and espionage. The campaign targets tech professionals on social media platforms like LinkedIn and X, where operators pose as recruiters representing well-known Web3 firms such as Coinbase, Robinhood, Uniswap, and Archblock.
The attack initiates with a staged 'skills assessment' on a fraudulent web portal, followed by a video interview on a spoofed meeting platform. During the call, candidates are prompted to authorize camera and microphone permissions, eventually being instructed to run a terminal command to 'update camera drivers', which triggers the infection.




