Researchers Uncover North Korean ‘ClickFake’ Campaign Targeting Web3 Pros
infosecurity-magazine.com Jul 21, 2026

Researchers Uncover North Korean ‘ClickFake’ Campaign Targeting Web3 Pros

AI-summarised brief · reviewed before publication

SOCRadar researchers identified a sophisticated social engineering campaign dubbed "ClickFake," attributed to the North Korean-aligned hacking group Famous Chollima. The operation specifically targets Web3 and cryptocurrency professionals through fraudulent job interviews on platforms like LinkedIn, Telegram, and Discord. Instead of mass phishing, attackers use personalized recruitment scams offering lucrative salaries to build trust. Candidates are directed to malicious web portals for mandatory skill assessments featuring real-time monitoring, countdown timers, and tab-switching warnings to create psychological pressure. The core deception involves a simulated technical error regarding camera or microphone access. Victims are instructed to copy and paste a diagnostic command into their system terminal to resolve the issue. On Windows systems, this command triggers an infection chain using PowerShell or curl to download a ZIP archive. A Visual Basic Script then unpacks a Python runtime, which loads PylangGhost, a customized remote access trojan, granting attackers full control over the victim’s device.

💡 Why It Matters

  • · The campaign exploits the high-stakes nature of tech recruitment by weaponizing professional ambition against security protocols.
  • · By forcing victims to manually execute malicious code under time pressure, attackers bypass traditional automated defenses that typically block unsolicited downloads.