North Korean hackers impersonate recruiters to deploy the PylangGhost Trojan targeting encryption professionals to steal credentials such as Metamask.

robot
Abstract generation in progress

On June 20, according to reports from Blockbeats, the threat intelligence research company Cisco Talos reported on Wednesday that North Korean hackers deployed a new type of Python remote access trojan named “PylangGhost” targeting crypto professionals through fake interviews disguised as recruitment for a certain platform and a certain DEX. This malware is associated with the notorious North Korean hacker group “Famous Chollima” (also known as “Wagemole”).

This malware can steal credentials from over 80 browser extensions, including Metamask and 1Password, and achieve persistent remote access. The attacks primarily target Windows systems and macOS users, while Linux systems are not affected by the current attacks.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 9
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)