According to reports, threat intelligence research agency Cisco Talos released its latest investigation results on June 20, revealing a targeted cyber attack against professionals in the crypto assets industry. A North Korean hacker group disguised as human resources representatives from well-known crypto platforms conducted fake job interviews and implanted a Python remote access Trojan known as "PylangGhost" into job seekers.



Research shows that this malware can extract user credentials from over 80 types of browser extensions, including popular encryption wallet Metamask and password management tool 1Password, and can establish a long-term remote access channel. This attack primarily targets Windows and macOS operating system users, while Linux system users have not yet been affected.

Security experts have linked this attack to the notorious hacker group "Famous Chollima" (also known as "Wagemole"). This incident serves as another reminder for Crypto Assets practitioners to remain highly vigilant during online recruitment activities, especially when it involves installing unknown programs.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Share
Comment
0/400
StopLossMastervip
· 06-22 15:10
Suckers are about to see fresh blood.
View OriginalReply0
BlockchainDecodervip
· 06-21 17:29
From the analysis of the attack payload, the technical complexity of the PylangGhost incident ranks in the top 25% among similar attacks. Readers are advised to refer to the MITRE ATT&CK framework T1059.006 to understand the characteristics of Python malicious script attacks.
View OriginalReply0
BlockchainFoodievip
· 06-20 07:51
talking about security backdoors... it's like leaving your kitchen door open while cooking a michelin-star defi recipe smh
Reply0
CountdownToBrokevip
· 06-20 07:45
Here comes the trap for the suckers again, right?
View OriginalReply0
DeFiDoctorvip
· 06-20 07:43
Consultation income: Another case of access credential leakage, it is recommended that web3 practitioners switch to Linux systems.
View OriginalReply0
GasFeeVictimvip
· 06-20 07:21
Suckers are suffering.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)