North Korean hackers target crypto industry workers with new information-stealing malware

2025/06/20 17:24

PANews June 20 news, according to Cointelegraph, Cisco Talos released a report on Wednesday saying that the North Korean hacker group "Famous Chollima" recently launched a new type of phishing attack against cryptocurrency practitioners. The organization tricked job seekers with blockchain experience in India and other places to install a Python remote control Trojan called "PylangGhost" by impersonating fake recruitment websites of companies such as Coinbase and Robinhood. The attacker induced the victim to execute malicious commands in the name of video interviews to steal wallet credentials and password manager data from more than 80 browser plug-ins such as MetaMask and TronLink. The malware has functions such as screenshots, file management, and system information collection, and has similar features to the previously discovered GolangGhost Trojan. Researchers have ruled out the possibility that the attacker used AI to generate code.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.