Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Hackers Steal Microsoft 365 Sessions Via Compromised Outlook Accounts
July 22, 2026
Spain Fines 23andMe €2.4M for 6.9M User Data Breach
July 22, 2026
Yubico YubiKey 5.8 Update Adds Secure Enterprise Workflows
July 22, 2026
Home/Threats/GolangGhost macOS Malware Steals Chrome Secrets and MetaMask Permissions
Threats

GolangGhost macOS Malware Steals Chrome Secrets and MetaMask Permissions

Key Takeaways A new malware campaign, attributed to North Korea’s Famous Chollima group, targets cryptocurrency and Web3 professionals. The campaign utilizes fake job interviews and skill...

Sarah simpson
Sarah simpson
July 22, 2026 4 Min Read
3 0

Key Takeaways

  • A new malware campaign, attributed to North Korea’s Famous Chollima group, targets cryptocurrency and Web3 professionals.
  • The campaign utilizes fake job interviews and skill assessments to deliver GolangGhost malware to macOS users and PylangGhost to Windows users.
  • GolangGhost is a remote access trojan that steals browser credentials, decrypts Chrome’s local database, and extracts data from crypto wallet extensions like MetaMask.
  • The malware can also modify MetaMask permissions within Chrome, potentially allowing attackers to exploit the extension’s trusted position for illicit activities.
  • Organizations and individuals in crypto, investment, legal, and advisory roles are highly susceptible due to their access to sensitive financial and corporate data.

Sophisticated Malware Campaign Targets Crypto and Web3 Professionals

A new, highly sophisticated malware campaign is actively targeting professionals in the cryptocurrency and Web3 sectors. This operation employs deceptive fake job interviews to distribute the GolangGhost remote access trojan (RAT) to macOS users, while Windows users are infected with PylangGhost. The primary objective of GolangGhost is to exfiltrate sensitive browser credentials, collect cryptocurrency wallet data, and establish persistent control over compromised macOS systems. Further details on the malware’s capabilities and attack vectors can be found in a comprehensive report.

Table Of Content

  • Key Takeaways
  • Sophisticated Malware Campaign Targets Crypto and Web3 Professionals
  • GolangGhost’s MacOS Attack Chain and Capabilities
  • The Deceptive “ClickFake” Interview Process
  • What You Should Do

SOCRadar, in a report shared with Cyber Security News (CSN), has linked this campaign to the North Korean-aligned threat group known as Famous Chollima, also referred to as Wagemole. This group has a history of financially motivated cyber operations, and this current campaign highlights their continued focus on high-value targets within the digital asset space.

GolangGhost’s MacOS Attack Chain and Capabilities

The attack on macOS systems begins when victims are tricked into pasting a malicious command into their Terminal. This command initiates a Bash script that performs several critical actions. It creates a hidden directory, downloads a fake “Intel driver” archive containing the GolangGhost payload, and then retrieves the Go compiler necessary to execute the malware. To ensure persistence, the script also establishes a Launch Agent, allowing GolangGhost to automatically restart after system reboots. This sophisticated deployment mechanism underscores the attackers’ understanding of macOS internals and their dedication to maintaining access.

Once active, GolangGhost leverages the macOS Keychain command-line utility to extract the master password used by Google Chrome. With this crucial secret, the malware can decrypt Chrome’s local database, thereby exposing all saved browser credentials and cookies. This stolen data can grant attackers unauthorized access to various online services, extending the impact beyond the initial system compromise. The ability to harvest such sensitive information highlights the severe risks posed by this malware, mirroring the dangers observed in other macOS credential-stealing malware.

Beyond browser data, GolangGhost actively seeks out data associated with cryptocurrency wallet extensions and password managers. This includes targeting MetaMask and other popular wallet extensions, allowing attackers to collect configuration settings and related data from Chrome profiles. A particularly concerning capability is GolangGhost’s ability to modify Chrome’s Secure Preferences file. After forcing the browser to close, the malware injects extensive permissions—such as access to active tabs, clipboard manipulation, web requests, and expanded storage—and assigns them directly to the MetaMask extension. This alteration could enable attackers to exploit MetaMask’s trusted position within the browser environment, potentially leading to unauthorized cryptocurrency transactions or further compromise of digital assets.

The Deceptive “ClickFake” Interview Process

The attackers employ a meticulously crafted social engineering scheme centered around fake job interviews, dubbed “ClickFake.” These interview pages are designed to pressure victims into rapid decision-making. They gather personal information, fingerprint the user’s browser and device, block mobile access, present timed assessment questions, and display warnings if candidates attempt to switch browser tabs. This creates a high-pressure environment, reducing the likelihood of victims scrutinizing suspicious requests.

The final stage of the deception involves a fabricated camera or microphone troubleshooting prompt during a supposed video recording. The page subtly swaps a benign command that the victim intends to copy with a malicious one, while visually presenting the harmless text in the Terminal to avoid raising suspicion. This technique, seen in recent ClickFix malware campaigns, demonstrates how attackers manipulate user actions for initial access. Additionally, the campaign deploys a counterfeit macOS application that prompts for administrator credentials under the guise of an update. These credentials are then transmitted to attacker-controlled infrastructure, providing yet another avenue for account takeover and complete device control.

The broader implications of this campaign are significant, extending beyond individual device compromise. Professionals in crypto, investment, legal, advisory, and business roles often possess direct access to digital wallets, corporate accounts, or highly sensitive information. Attackers can leverage this access to steal digital assets, execute fraudulent transactions, or penetrate deeper into organizational networks. This attack highlights a recurring threat pattern, with similar fake recruiter malware campaigns consistently targeting the crypto sector.

What You Should Do

  • Employee Training: Educate all staff, particularly non-technical personnel, to recognize and report suspicious job solicitations, especially those involving unusual technical troubleshooting steps or requests to execute commands in the terminal.
  • Restrict Personal Activities on Corporate Devices: Implement and enforce policies that prohibit personal job searching or the installation of unapproved software on company-issued devices.
  • Monitor for Anomalous Activity: Security teams should actively monitor for the creation of unexpected Launch Agents, unauthorized modifications to browser preferences, and the presence of suspicious compiled modules or dynamic libraries.
  • Scrutinize Recruitment Software: Exercise extreme caution with third-party recruitment software packages. Verify their legitimacy and security posture before integrating them into hiring processes.
  • Multi-Factor Authentication (MFA): Enable MFA on all accounts, especially those linked to cryptocurrency exchanges, wallets, and sensitive corporate systems, to add an extra layer of security.
  • Regular Backups: Maintain regular, encrypted backups of critical data to mitigate the impact of data theft or ransomware attacks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarePatchSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Google Chrome Patches 12 Vulnerabilities, Fixing Browser Attack Risk

Next Post

Russian Hacker Transforms Claude AI into a Pentesting Tool

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GolangGhost macOS Malware Steals Chrome Secrets and MetaMask Permissions
July 22, 2026
Google Chrome Patches 12 Vulnerabilities, Fixing Browser Attack Risk
July 22, 2026
Critical ServiceNow Vulnerability Actively Exploited in the Wild
July 22, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us