DPRK’s Famous Chollima Deploys RATs Through ClickFake Job Interviews

2026-07-20 SOCRadar

https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/

Thumbnail for DPRK’s Famous Chollima Deploys RATs Through ClickFake Job Interviews

Famous Chollima, a North Korean-aligned actor also known as Wagemole, uses fake cryptocurrency and Web3 job interviews to pressure targets into executing clipboard-substituted ClickFix commands. Windows victims receive a Nuitka-compiled PylangGhost RAT, while macOS victims receive GolangGhost and a SwiftUI credential harvester, with both chains establishing persistence and supporting remote commands, file transfer, and encrypted C2. The implants steal browser credentials and cryptocurrency-wallet extension data, and the macOS variant can manipulate Chrome preferences associated with MetaMask. Victim-specific invitation gating, browser fingerprinting, countdown pressure, and remotely triggered camera errors help conceal the infrastructure and increase victim compliance.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://95.216.92.207:8080/gette… 2026-07-20 2026-07-20
URL http://95.216.92.207:8080 2026-07-20 2026-07-20
URL https://app.breezyhr.us/v223/ap… 2026-07-20 2026-07-20
URL https://app.breezyhr.us/v223/mi… 2026-07-20 2026-07-20
URL https://app.breezyhr.us/v223 2026-07-20 2026-07-20
DOMAIN nvidiadriver.net 2026-07-20 2026-07-20
DOMAIN app.breezyhr.us 2026-07-20 2026-07-20
IPv4 95.216.92.207 2026-07-20 2026-07-20

Related Actors

Related Reports

« Back