ClickFake Interview attack chain | Image: SOCRadar Threat Research Unit
At a glance
| Threat actor | Famous Chollima, also called Wagemole; North Korea-aligned |
| Activity type | Social engineering via fake job interviews; ClickFix lures delivering RATs |
| Targets | Crypto and Web3 professionals, mostly in non-technical roles |
| Scale | SOCRadar reports $643 million in crypto stolen by DPRK actors this year; victim count not disclosed |
| Status | Vendor attribution, not an indictment; no arrests reported |
| Source | SOCRadar Threat Research Unit, with Cisco Talos |
TL;DR
SOCRadar published new analysis of the ClickFake Interview campaign on July 21, 2026. Fake recruiters walk crypto professionals through a bogus skill assessment. It ends with a copy-and-paste command that installs a remote access trojan.
What happened
The lure starts on social media. Operators pose as recruiters on LinkedIn, Discord, Telegram, or email. They pitch a well-paid role, then send an invitation to a skill assessment. That assessment sits on attacker-controlled infrastructure.
Some operators invent front companies. Others impersonate real firms in crypto and HR through lookalike domains. The fake test then asks the candidate to record a video answer. At that point, a camera error appears on screen.
That error is the trap. The panel shows troubleshooting steps and a command to copy. Crucially, the page swaps the clipboard contents when the target copies the text. The victim sees a harmless driver update, yet pastes something else entirely.
A panel built to pressure people
The assessment kit is engineered for conversion, not just deception. It blocks mobile visitors, since the payloads only run on desktops. It also checks each invite link, deflecting scanners to a fake 404 page.
Other features target the candidate’s nerves. A countdown timer creates urgency. If the target switches tabs, a warning modal implies someone is watching. Operators can even trigger the fake camera error manually while observing the test in real time.
The panel harvests personal data before any malware lands. It collects names, emails, phone numbers, social profiles, and work history. SOCRadar suggests that data may feed North Korea‘s fraudulent IT worker operation.
Who is behind it
SOCRadar attributes the ClickFake Interview activity to Famous Chollima, a North Korea-aligned group. Confidence here is reasonably strong. Cisco Talos linked both RAT families to the same actor in earlier research. CrowdStrike tracks the group, and MITRE ATT&CK catalogs its related Contagious Interview campaign.
That said, this remains vendor attribution rather than a criminal charge. No arrests or indictments tie named individuals to this specific campaign. Talos previously noted the operation goes after people with crypto and blockchain experience, with many earlier victims in India.
Impact and scale
The payloads split by platform. Windows targets receive PylangGhost, a Python RAT. macOS targets get GolangGhost plus a fake login window that requests an administrator password. Both families share six modules, including a C2 component and a credential stealer.
The stealer aims squarely at money. It hunts more than thirty browser extensions, covering wallets like MetaMask, Coinbase Wallet, and Trust Wallet, plus password managers. On Windows, it attempts to defeat Chrome’s App-Bound Encryption to unlock saved passwords.
Detection evasion has improved too. The attackers now compile Python payloads into native modules with Nuitka. The macOS variant checks for virtual machines before reporting back. Infrastructure, by contrast, looks disposable, “emphasizing speed and scale, rather than operational security and infrastructure resilience.”
Companies face risk here, not only individuals. Employees often job-hunt on work laptops. A compromised personal session can therefore open a path toward corporate systems.
How to stay protected
Train non-technical staff first, since they are the intended targets. The core rule is simple. No legitimate employer fixes a webcam by having you paste commands into a terminal.
Treat unsolicited recruiter outreach with care, especially when it moves fast toward a timed test. Verify companies independently rather than through links in the message. Keep personal job hunting off corporate devices where possible.
Defenders should also watch for script interpreters and compilers appearing where they do not belong. SOCRadar’s full technical analysis lists indicators worth hunting. Because these payloads ship as extension modules and dynamic libraries, signature-only detection will keep falling short.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.