BTCC / BTCC Square / Global Cryptocurrency /
North Korean Hackers Target Crypto Workers with ’PylangGhost’ Malware via Fake Job Sites

North Korean Hackers Target Crypto Workers with ’PylangGhost’ Malware via Fake Job Sites

Published:
2025-06-20 06:39:02
9
3

Cisco Talos has uncovered a new Python-based malware, 'PylangGhost,' deployed by the North Korean hacking group Famous Chollima. The malware specifically targets job seekers in the cryptocurrency industry, infiltrating their hardware through fake job postings.

The threat mirrors the GolangGhost RAT, discovered in December 2024, and has been actively used to compromise Windows systems. A Golang variant remains in use for MacOS targets. Open-source data points to India as the primary victim region.

Famous Chollima, also known as 'Wagemole,' employs social engineering tactics, creating counterfeit job sites impersonating major crypto firms to steal passwords and access digital wallets.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users