Famous Chollima ClickFake Interview recruitment scam campaign
Campaign
Summary
Hide ▲
Show ▼
A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote access trojans. The operation uses ClickFix-style lures to trick candidates into running terminal commands, turning the interview flow into a malware delivery chain. The approach raises immediate risk to personal devices, saved credentials, and digital assets handled by the targets.
Related Happenings
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
Campaign
H score38
First: 24.07.2026 18:12
Last: 24.07.2026 18:12
Sources 1
About this happening:
BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
CampaignAbout this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware Activity
H score29
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
How related:
The malicious terminal command fetches and executes GolangGhost, a remote access trojan written in Go.
About this happening:
The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware ActivityHow related: The malicious terminal command fetches and executes GolangGhost, a remote access trojan written in Go.
About this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
GPPStorm Google Partners enrollment phishing campaign
Campaign
H score33
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
GPPStorm Google Partners enrollment phishing campaign
CampaignAbout this happening: GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware Activity
H score29
First: 01.04.2026 16:30
Last: 01.04.2026 16:30
Sources 1
About this happening:
The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware ActivityAbout this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Timeline
-
21.07.2026 12:30 2 articles · 13d ago
Famous Chollima targets Web3 professionals with ClickFake Interview scam
Initial DisclosureSOCRadar identified a North Korean-aligned social-engineering campaign by Famous Chollima, also known as Wagemole, that targets Web3 and cryptocurrency professionals with fake job interviews, ClickFix lures, and malicious assessment portals. The delivery chain pushes candidates through recruiter outreach on LinkedIn, Telegram, Discord, and direct email, then uses platform prompts and terminal commands to deliver PylangGhost on Windows and GolangGhost on macOS.
Show sources
- Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros — www.infosecurity-magazine.com — 21.07.2026 12:30
- Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros — www.infosecurity-magazine.com — 21.07.2026 12:30