THE ClickFake Interview campaign, attributed to the North Korean group Famous Chollima, targets crypto professionals through social engineering tactics. Attackers pose as recruiters on platforms like LinkedIn and email, inviting targets to fake skill assessments that install remote access trojans (RATs) such as PylangGhost and GolangGhost. These payloads gather personal data and seek to steal sensitive information from digital wallets and password managers.
With an estimated $643 million in crypto theft by DPRK this year, the campaign emphasizes urgency and deception to compromise victims. Companies are at risk as employees may inadvertently expose corporate systems. To enhance protection, individuals should verify job offers independently and refrain from using corporate devices for personal job searches.