GolangGhost macOS Malware Steals Chrome Secrets and MetaMask Permissions
Key Takeaways A new malware campaign, attributed to North Korea’s Famous Chollima group, targets cryptocurrency and Web3 professionals. The campaign utilizes fake job interviews and skill...
Key Takeaways
- A new malware campaign, attributed to North Korea’s Famous Chollima group, targets cryptocurrency and Web3 professionals.
- The campaign utilizes fake job interviews and skill assessments to deliver GolangGhost malware to macOS users and PylangGhost to Windows users.
- GolangGhost is a remote access trojan that steals browser credentials, decrypts Chrome’s local database, and extracts data from crypto wallet extensions like MetaMask.
- The malware can also modify MetaMask permissions within Chrome, potentially allowing attackers to exploit the extension’s trusted position for illicit activities.
- Organizations and individuals in crypto, investment, legal, and advisory roles are highly susceptible due to their access to sensitive financial and corporate data.
Sophisticated Malware Campaign Targets Crypto and Web3 Professionals
A new, highly sophisticated malware campaign is actively targeting professionals in the cryptocurrency and Web3 sectors. This operation employs deceptive fake job interviews to distribute the GolangGhost remote access trojan (RAT) to macOS users, while Windows users are infected with PylangGhost. The primary objective of GolangGhost is to exfiltrate sensitive browser credentials, collect cryptocurrency wallet data, and establish persistent control over compromised macOS systems. Further details on the malware’s capabilities and attack vectors can be found in a comprehensive report.
Table Of Content
SOCRadar, in a report shared with Cyber Security News (CSN), has linked this campaign to the North Korean-aligned threat group known as Famous Chollima, also referred to as Wagemole. This group has a history of financially motivated cyber operations, and this current campaign highlights their continued focus on high-value targets within the digital asset space.
GolangGhost’s MacOS Attack Chain and Capabilities
The attack on macOS systems begins when victims are tricked into pasting a malicious command into their Terminal. This command initiates a Bash script that performs several critical actions. It creates a hidden directory, downloads a fake “Intel driver” archive containing the GolangGhost payload, and then retrieves the Go compiler necessary to execute the malware. To ensure persistence, the script also establishes a Launch Agent, allowing GolangGhost to automatically restart after system reboots. This sophisticated deployment mechanism underscores the attackers’ understanding of macOS internals and their dedication to maintaining access.
Once active, GolangGhost leverages the macOS Keychain command-line utility to extract the master password used by Google Chrome. With this crucial secret, the malware can decrypt Chrome’s local database, thereby exposing all saved browser credentials and cookies. This stolen data can grant attackers unauthorized access to various online services, extending the impact beyond the initial system compromise. The ability to harvest such sensitive information highlights the severe risks posed by this malware, mirroring the dangers observed in other macOS credential-stealing malware.
Beyond browser data, GolangGhost actively seeks out data associated with cryptocurrency wallet extensions and password managers. This includes targeting MetaMask and other popular wallet extensions, allowing attackers to collect configuration settings and related data from Chrome profiles. A particularly concerning capability is GolangGhost’s ability to modify Chrome’s Secure Preferences file. After forcing the browser to close, the malware injects extensive permissions—such as access to active tabs, clipboard manipulation, web requests, and expanded storage—and assigns them directly to the MetaMask extension. This alteration could enable attackers to exploit MetaMask’s trusted position within the browser environment, potentially leading to unauthorized cryptocurrency transactions or further compromise of digital assets.
The Deceptive “ClickFake” Interview Process
The attackers employ a meticulously crafted social engineering scheme centered around fake job interviews, dubbed “ClickFake.” These interview pages are designed to pressure victims into rapid decision-making. They gather personal information, fingerprint the user’s browser and device, block mobile access, present timed assessment questions, and display warnings if candidates attempt to switch browser tabs. This creates a high-pressure environment, reducing the likelihood of victims scrutinizing suspicious requests.
The final stage of the deception involves a fabricated camera or microphone troubleshooting prompt during a supposed video recording. The page subtly swaps a benign command that the victim intends to copy with a malicious one, while visually presenting the harmless text in the Terminal to avoid raising suspicion. This technique, seen in recent ClickFix malware campaigns, demonstrates how attackers manipulate user actions for initial access. Additionally, the campaign deploys a counterfeit macOS application that prompts for administrator credentials under the guise of an update. These credentials are then transmitted to attacker-controlled infrastructure, providing yet another avenue for account takeover and complete device control.
The broader implications of this campaign are significant, extending beyond individual device compromise. Professionals in crypto, investment, legal, advisory, and business roles often possess direct access to digital wallets, corporate accounts, or highly sensitive information. Attackers can leverage this access to steal digital assets, execute fraudulent transactions, or penetrate deeper into organizational networks. This attack highlights a recurring threat pattern, with similar fake recruiter malware campaigns consistently targeting the crypto sector.
What You Should Do
- Employee Training: Educate all staff, particularly non-technical personnel, to recognize and report suspicious job solicitations, especially those involving unusual technical troubleshooting steps or requests to execute commands in the terminal.
- Restrict Personal Activities on Corporate Devices: Implement and enforce policies that prohibit personal job searching or the installation of unapproved software on company-issued devices.
- Monitor for Anomalous Activity: Security teams should actively monitor for the creation of unexpected Launch Agents, unauthorized modifications to browser preferences, and the presence of suspicious compiled modules or dynamic libraries.
- Scrutinize Recruitment Software: Exercise extreme caution with third-party recruitment software packages. Verify their legitimacy and security posture before integrating them into hiring processes.
- Multi-Factor Authentication (MFA): Enable MFA on all accounts, especially those linked to cryptocurrency exchanges, wallets, and sensitive corporate systems, to add an extra layer of security.
- Regular Backups: Maintain regular, encrypted backups of critical data to mitigate the impact of data theft or ransomware attacks.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.