CryptoMediaClub
Wednesday, December 3, 2025
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
  • en English
    • ar العربية
    • zh-CN 简体中文
    • cs Čeština‎
    • nl Nederlands
    • en English
    • et Eesti
    • fr Français
    • de Deutsch
    • iw עִבְרִית
    • it Italiano
    • ja 日本語
    • ko 한국어
    • lv Latviešu valoda
    • pl Polski
    • pt Português
    • ru Русский
    • sk Slovenčina
    • es Español
    • sv Svenska
    • uk Українська
No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
  • en English
    • ar العربية
    • zh-CN 简体中文
    • cs Čeština‎
    • nl Nederlands
    • en English
    • et Eesti
    • fr Français
    • de Deutsch
    • iw עִבְרִית
    • it Italiano
    • ja 日本語
    • ko 한국어
    • lv Latviešu valoda
    • pl Polski
    • pt Português
    • ru Русский
    • sk Slovenčina
    • es Español
    • sv Svenska
    • uk Українська
No Result
View All Result
CryptoMediaClub
No Result
View All Result
Home All news

North Korean Hackers Pose as Coinbase Recruiters to Steal Crypto with ‘PylangGhost’ Trojan

20.06.2025
A A
0
118
VIEWS
ShareShare

North Korean cybercriminals have escalated their targeting of crypto professionals with a sophisticated new Python-based malware called PylangGhost.

They deploy elaborate fake job interview schemes that impersonate major companies, including Coinbase, Robinhood, and Uniswap, to steal credentials from over 80 browser extensions and crypto wallets.

Cisco Talos researchers discovered this latest campaign by the infamous “Famous Chollima” threat group.

The attacks primarily focus on crypto and blockchain professionals in India. They lure victims through fraudulent skill-testing websites that appear legitimate but ultimately trick users into executing malicious commands disguised as video driver installations for fake interview recordings.

North Korean Hackers Pose as Coinbase Recruiters to Steal Crypto with 'PylangGhost' Trojan
Source: Talos Intelligence

The PylangGhost campaign represents the latest escalation in North Korea’s systematic targeting of the cryptocurrency industry, which has generated over $1.3 billion in stolen funds across 47 separate incidents in 2024 alone, according to Chainalysis data.

PylangGhost Trojan: From Fake Interviews to Full System Compromise

The PylangGhost operation is built on sophisticated social engineering tactics, beginning with carefully crafted fake recruiter outreach that targets specific expertise in cryptocurrency and blockchain technologies.

Victims receive invitations to skill-testing websites built using the React framework that closely mimic legitimate company assessment platforms.

These websites contain technical questions designed to validate the target’s professional background and create an authentic interview experience.

The psychological manipulation reaches its peak when candidates complete assessments and are invited to record video interviews. The site requests camera access through a seemingly innocuous button click.

North Korean Hackers Pose as Coinbase Recruiters to Steal Crypto with 'PylangGhost' Trojan
Source: Talos Intelligence

Once camera access is requested, the site displays platform-specific instructions for downloading alleged video drivers. Different command shells are provided based on browser fingerprinting, including PowerShell or Command Shell for Windows users and Bash for macOS systems.

North Korean Hackers Pose as Coinbase Recruiters to Steal Crypto with 'PylangGhost' Trojan
Source: Talos Intelligence

The malicious command downloads a ZIP file containing the PylangGhost modules and a Visual Basic Script that unzips a Python library. It then launches the Trojan through a renamed Python interpreter, using “nvidia.py” as the execution file.

The malware’s capabilities extend far beyond simple credential theft. It establishes persistent access through registry modifications that ensure the RAT launches every time the user logs into the system.

PylangGhost generates unique system GUIDs for communication with command-and-control servers while implementing sophisticated data exfiltration capabilities targeting over 80 browser extensions, including critical cryptocurrency wallets such as Metamask, Phantom, Bitski, TronLink, and MultiverseX.

The Trojan’s modular design enables remote file upload and download, OS shell access, and comprehensive browser data harvesting, including stored credentials, session cookies, and extension data from password managers like 1Password and NordPass.

A Global Campaign Threatening Crypto Industry Security

The PylangGhost discovery is just the visible portion of a massive, coordinated North Korean cyber campaign that has fundamentally threatened crypto businesses and professionals worldwide.

Intelligence agencies from Japan, South Korea, and the United States have documented how North Korean-backed groups, primarily the notorious Lazarus collective, orchestrated sophisticated operations that resulted in the theft of at least $659 million through cryptocurrency heists in 2024 alone.

🚨 North Korean cyber spies reportedly set up fake US firms to deploy malware targeting crypto developers, violating Treasury sanctions.#NorthKorea #CyberSecurity https://t.co/TvCmrspaep

— Cryptonews.com (@cryptonews) April 25, 2025

Recent enforcement actions have revealed the true scope of North Korean cyber operations. The FBI has seized BlockNovas LLC’s domain, which was used to establish legitimate-appearing corporate entities and conduct long-term deception campaigns.

The recent $50 million Radiant Capital hack also demonstrated the effectiveness of these tactics when North Korean operatives successfully posed as former contractors and distributed malware-laden PDFs to engineers.

👾 A North Korean hacker impersonated as a job seeker for an engineering role at Kraken, who attempted to infiltrate the ranks of the exchange.#Kraken #CryptoHacker #NorthKoreanHackerhttps://t.co/IorY67EV3L

— Cryptonews.com (@cryptonews) May 2, 2025

In contrast, while these tactics remain effective, Kraken’s recent disclosure of successfully identifying and thwarting a North Korean job applicant shows that major exchanges are now implementing enhanced screening procedures to detect infiltration attempts.

Similarly, BitMEX recently conducted a counterintelligence operation that exposed significant operational weaknesses within the Lazarus Group. This included exposed IP addresses and accessible databases that revealed the group’s fragmented structure with varying technical capabilities across different cells.

The international response has intensified dramatically, with South Korea and the European Union formalizing cybersecurity cooperation agreements specifically targeting North Korean cryptocurrency operations.

At the same time, U.S. authorities have expanded forfeiture actions to recover over $7.7 million in crypto assets earned through networks of covert IT workers.

🇰🇵 Japan is preparing to urge G7 nations to launch a coordinated response against North Korea’s growing involvement in cryptocurrency theft.#Japan #NorthKoreahttps://t.co/0WG78wEsx4

— Cryptonews.com (@cryptonews) June 12, 2025

The mounting threat has prompted discussions at the highest levels of international diplomacy, with G7 leaders expected to address North Korea’s escalating cyberattacks at upcoming summits as member states seek coordinated strategies to protect global financial infrastructure.

The post North Korean Hackers Pose as Coinbase Recruiters to Steal Crypto with ‘PylangGhost’ Trojan appeared first on Cryptonews.

Share9Tweet6ShareSharePin2

Related Posts

BNB Price Prediction: Binance Coin is Approaching the Best Buying Level in 6 Months – What Happens Next?
All news

BNB Price Prediction: Binance Coin is Approaching the Best Buying Level in 6 Months – What Happens Next?

03.12.2025
0

Binance Coin is flashing its strongest buy signal in six months, a trend line that has underpinned some of the...

Read moreDetails
The Day Trading Died: Why AGI Might Be the Last Market Maker

The Day Trading Died: Why AGI Might Be the Last Market Maker

02.12.2025
Bank of America Just Unleashed Bitcoin ETFs to 15,000+ Advisers – Here’s Why It Matters

Bank of America Just Unleashed Bitcoin ETFs to 15,000+ Advisers – Here’s Why It Matters

02.12.2025
Crypto VC Funding Surges in November on Naver’s $10.3B Deal

Crypto VC Funding Surges in November on Naver’s $10.3B Deal

02.12.2025
WEEX Launches Triple Incentives Campaign: Deposit Boost, Sign-Up Coupons, and Trading Rewards

WEEX Launches Triple Incentives Campaign: Deposit Boost, Sign-Up Coupons, and Trading Rewards

02.12.2025
Load More
Next Post
China Promotes Digital Yuan as International Currency

China Promotes Digital Yuan as International Currency

0 0 votes
Рейтинг статьи
Subscribe
Notify of
guest
guest
0 комментариев
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recommended

How The Police Apprehended Silk Road’s 50,000 Bitcoin Thief

2 years ago
Why did Bitcoin drop? Analysts Point to 5 Potential Reasons.

Why did Bitcoin drop? Analysts Point to 5 Potential Reasons.

2 years ago
Crypto Whales Bet on New Web3 VR Crypto – The Next Major Trend?

Crypto Whales Bet on New Web3 VR Crypto – The Next Major Trend?

2 years ago
Cardano Price Prediction: Leios Upgrade Targets Solana-Level Speed – Could ADA 50x Before 2026?

Cardano Price Prediction: Leios Upgrade Targets Solana-Level Speed – Could ADA 50x Before 2026?

4 months ago

Categories

  • All news
  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
No Result
View All Result

Highlights

Crypto VC Funding Surges in November on Naver’s $10.3B Deal

WEEX Launches Triple Incentives Campaign: Deposit Boost, Sign-Up Coupons, and Trading Rewards

Goldman Sachs to Acquire Bitcoin ETF Issuer Innovator in $2B Deal

FDIC to Implement US Stablecoin Rule Framework This Month, Acting Chair Says

BitMine Doubles Down on Ether With $70M Buying Spree Despite Market Slump

Next Altcoin to Turn $100 into $10,000 – 1 December

Trending

BNB Price Prediction: Binance Coin is Approaching the Best Buying Level in 6 Months – What Happens Next?
All news

BNB Price Prediction: Binance Coin is Approaching the Best Buying Level in 6 Months – What Happens Next?

03.12.2025
0

Binance Coin is flashing its strongest buy signal in six months, a trend line that has underpinned...

The Day Trading Died: Why AGI Might Be the Last Market Maker

The Day Trading Died: Why AGI Might Be the Last Market Maker

02.12.2025
Bank of America Just Unleashed Bitcoin ETFs to 15,000+ Advisers – Here’s Why It Matters

Bank of America Just Unleashed Bitcoin ETFs to 15,000+ Advisers – Here’s Why It Matters

02.12.2025
Crypto VC Funding Surges in November on Naver’s $10.3B Deal

Crypto VC Funding Surges in November on Naver’s $10.3B Deal

02.12.2025
WEEX Launches Triple Incentives Campaign: Deposit Boost, Sign-Up Coupons, and Trading Rewards

WEEX Launches Triple Incentives Campaign: Deposit Boost, Sign-Up Coupons, and Trading Rewards

02.12.2025
  • All news
  • Altcoins
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
  • Analysis
Editor: cryptomediaclub.com@gmail.com
Advertising: digestmediaholding@gmail.com

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

wpDiscuz