A new malware campaign is targeting cryptocurrency and Web3 professionals through fake job interviews.
The operation delivers GolangGhost, a remote access trojan that can steal browser credentials, collect wallet data, and give attackers control of infected macOS systems.
The attackers pose as recruiters, offer attractive roles, and direct targets to fake online skill assessments.
At the final video-recording stage, the site displays a false camera error and persuades victims to copy and paste a supposed fix into their Mac Terminal.
SOCRadar said in a report shared with Cyber Security News (CSN) that the campaign is linked to the North Korean-aligned Famous Chollima group, also tracked as Wagemole.
The campaign delivers PylangGhost to Windows users and GolangGhost to macOS users through the same deceptive recruitment process.
Financially motivated DPRK campaigns (Source – SOCRadar)
The risk extends beyond a single compromised device. People working in crypto, investment, legal, advisory, and business roles may hold direct access to wallets, company accounts, or sensitive information that attackers can use to steal digital assets or move deeper into an organization.
Similar fake recruiter malware campaigns have repeatedly targeted the crypto sector.
GolangGhost Steals Chrome Secrets
On macOS, the copied command starts a Bash script that creates a hidden working directory, downloads a fake Intel driver archive, and retrieves the Go compiler needed to run GolangGhost.
The script also establishes persistence through a Launch Agent, allowing the malware to restart after a reboot.
GolangGhost can use the macOS Keychain command-line utility to retrieve Chrome’s stored master password. It then applies that secret to decrypt Chrome’s local database, exposing saved browser credentials and cookies that may grant access to online services.
ClickFake Interview attack chain (Source – SOCRadar)
This mirrors the danger seen in macOS credential stealing malware, which has also targeted browser data and wallet information.
The malware also searches for browser extension data associated with cryptocurrency wallets and password managers.
Its targets include MetaMask and several other wallet extensions, enabling attackers to collect extension settings and related data from Chrome profiles.
More concerningly, GolangGhost can alter Chrome’s Secure Preferences file after forcing the browser to close.
The malware injects broad permissions, including access to active tabs, clipboard writing, web requests, and expanded storage, then assigns them to the MetaMask extension. That change could let attackers abuse the wallet extension’s trusted browser position.
Fake Interviews Drive Infection
The ClickFake interview pages are designed to make victims act quickly. They collect personal information, fingerprint the visitor’s browser and device, block mobile users, show timed assessment questions, and display warnings when candidates switch browser tabs.
At the final step, the attackers present a realistic camera or microphone troubleshooting prompt.
The page replaces the harmless command copied by the victim with a malicious one, while displaying the expected text in Terminal to reduce suspicion.
Recent ClickFix malware campaigns show how this approach turns a victim’s own action into initial access.
Sample ClickFix instruction from the ClickFake Campaign (Source – SOCRadar)
The campaign also launches a fake macOS application that requests administrator credentials under the guise of an update.
Those credentials are sent to attacker-controlled infrastructure, adding another path to account takeover and device control.
Organizations should train staff, especially non-technical employees, to treat unsolicited interview requests and copy-and-paste troubleshooting steps as warning signs.
Security teams should prevent personal job hunting on corporate devices, review unexpected Launch Agents and browser-preference changes, and use detections that inspect suspicious compiled modules and dynamic libraries.
The threat also reinforces why teams should avoid untrusted recruitment software packages during hiring conversations.
Indicators of Compromise (IoCs):-
TypeIndicatorDescriptionDomainpaxos-apply.comFake recruitment infrastructureDomaincameradriverupdates.comFake recruitment infrastructureDomainhighmatch.proFake recruitment infrastructureDomainhighmatch.cloudFake recruitment infrastructureDomaintailora.orgFake recruitment infrastructureDomainbreezyhr.usTyposquatted recruitment platformDomainrolevia.usFake recruitment infrastructureDomainmedincahub.comFake recruitment infrastructureDomaincincopa.orgFake recruitment infrastructureDomainknockri.usFake recruitment infrastructureDomainspiralboard.comFake recruitment infrastructureDomainkaltura.studioFake recruitment infrastructureDomainpaxos-video-interviews.comFake recruitment infrastructureDomainvideohirepro.comFake recruitment infrastructureDomainevaluateproficiency.comFake recruitment infrastructureDomainpaxos-video-recording.comFake recruitment infrastructureDomainvideo-hiring.comFake recruitment infrastructureDomainvervoe.appFake recruitment infrastructureDomaincanditech.usFake recruitment infrastructureDomainhirvexo.comFake recruitment infrastructureDomainhiring-you.comFake recruitment infrastructureDomaingumlet.usFake recruitment infrastructureDomainsurvicate.usFake recruitment infrastructureDomainziggeo.techCampaign infrastructureDomaininsighboard.comCampaign infrastructureDomainzavnia.usCampaign infrastructureDomainmettl.usCampaign infrastructureDomaintecmlny.comCampaign infrastructureDomainzynoracreative.comCampaign infrastructureDomainworkbright.usCampaign infrastructureDomainme-c0h.pages.devCampaign infrastructureDomainevaluza.comCampaign infrastructureDomainevaluino.comCampaign infrastructureDomainnvidiadriver.netPayload hosting domainIP Address95.216.92.207Command-and-control infrastructureURLhxxp://nvidiadriver.net/verv1432/drivers/intel-driver-xd7d.zipGolangGhost payload archiveURLhxxp://95.216.92.207:8080Command-and-control endpointURLhxxp://95.216.92.207:8080/gettextCredential exfiltration endpointSHA-25696ce1b7f2026dfd3dbb806c246c27ce3b105a9e78482956fae42258980425cd0ClickFix-related fileSHA-256b9a8ae1e6d2c875e21c77f3b9255ca0b3b0b3e0addbb2c3c865e5b95eb734d22winPatch-related fileSHA-256466170079e4b9e26e41a25ca45ff8a7f6cc9b3e9e7f2beda99f3dd042e72c1bupdate.vbsSHA-256164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3audiodriver moduleSHA-256df6669bd504ce6b0e303be7ee47f2ebbc062989c88c41f0a3f436044a24869798config moduleSHA-25650ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdfapi moduleSHA-2563c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2command moduleSHA-256282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990util moduleSHA-25617832aa629524ef6e8d8d6e9b6b902a8d324b559e3c36dbd0e221ab1690be871auto moduleSHA-2560ca62fe52a895bad73a14f1a455e1bead18b8c256749d727c2678924298f7ee8macPatch.shSHA-256617779f417c1850c08ed55ba49e2317aed0e1e911fca8bf8f348189ee4ebdb97drivfixer.shSHA-256ee59683f2ab7ba05da5443a153aee221af08ba884461f74dd8b114c0d10febbebmain.goSHA-256337dfb06e08ac8ceb47728b50de006ef82f5e61fa245494210a362bab15859fcoreiter.goSHA-256f53567c1a8885925393a1771cded2ff2c8ef4ab38da1bf97d36f153f81f72e80instancecheck.goSHA-25695983760b571631e1da0f52f51c7a274f2a34e44de5e3d10cadcf8b30edf959ccommandstackcmd.goSHA-2566110ea43d734a296a8e5676192c56cdbdad11c94c3eecda7b55a4672e16d35d4configconstants.goSHA-2566295839b6c9414d9cd0f2402f4cd72e219f75cc4dfac720cec297fddc4f20ff2utilcompress.goSHA-2566850cdb307fc72e052719939efbf705beb8d50775b260a18aff0adba536d7deatransporthtxp.goSHA-2564387b79045065622e7fd643b65d85998f092c4b32e53633d36bd7ef46181cbe2autobasic.goSHA-2560827606854b6fd7fa73f13f2e453d9720d79c63e89308cfed0b577a16d84bccdautchromechangepref.goSHA-256756846dfa3c258807b6962bb66373a543aa6b4ba0a35ffc4a526e4b07a84d9dcautochromecookiedarwin.goSHA-256319adf187bce5bd85dbb5b06f99ce78baa807af590feaed44a6f932d4d5b9003autochromecookieother.goSHA-256d1934fdd449b6e8124b632f680cbe6893ac39e740559b1882641204040c70a99autochromecookiewin.goSHA-25647a3ce02388c845e5f1ed8f4d3673e2c99a643b88d3f2fa06cbfe0c78502264dautochromegather.goSHA-2561cee591c63d7fd8ee963abb29789c3ee41eb42cc77470964a00ea15be4b51341CodeFixerNow.appSHA-2569e465904503815c27397e082fd5ca8eb30d99d8d256c6a0949696d1830c8bb53CodeFixerNow.debug.dylib
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposuremalware to businesses an
The post GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions appeared first on Cyber Security News.



