
NORTH Korean hackers are using fraudulent cryptocurrency job interviews to deliver the PylangGhost and GolangGhost remote access trojans onto victims’ machines, according to a SOCRadar report.
The attackers pose as recruiters on LinkedIn or via email, directing targets to fake skill‑assessment portals that prompt users to run malicious commands, which then deploy either the Python‑based PylangGhost or the Go‑based GolangGhost RAT on Windows hosts.
These RATs harvest system information, keystrokes and files from password managers and cryptocurrency applications, sending the data to attacker‑controlled servers; no public CVE identifiers have been assigned to the tools, indicating the threat relies purely on social engineering rather than a software vulnerability (Infosecurity Magazine).
Researchers first observed the activity in late July 2026 and note that the operation fits a broader trend of DPRK‑linked groups using bogus employment offers to fund regime finances, with an estimated $643 million in crypto theft attributed to North Korea this year.
Individuals should verify any unsolicited job offer by contacting the purported company through official channels before clicking links or downloading files, and employers are advised to restrict the use of corporate equipment for personal job‑search activities and to enforce endpoint detection rules that block execution of unknown scripts from web portals.
Security teams can monitor for outbound connections to newly registered domains associated with the campaign and apply application‑control policies to prevent unsigned Python or Go binaries from running, while educating staff about tell‑tale signs of fake interviews such as urgent timelines, requests for technical tests on unfamiliar sites and poor language quality.