• Trending
  • Comments
  • Latest
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Bitcoin ETF Flows surge as Fidelity, ARK & BlackRock attract $667M in one day

Bitcoin ETF Flows surge as Fidelity, ARK & BlackRock attract $667M in one day

05/20/2025
Just In: LastPass Hackers Strike Again Ahead of Christmas, Losses Near $45M

New York Post X account hacked in high-profile breach, triggers cybersecurity scrutiny

05/05/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2

Hello world!

1
Peter Brandt Warns of Major Ethereum (ETH) Crash to $1,651 in Latest Ethereum (ETH) Price Prediction

Ethereum Merge Fades: Supply Surge May Lead to Price Dip, Expert Warns, as ETF Hype Loses Steam

1
create a landscape image illustrating this with pictures, not texts. Use a real human figure and make the entire composition look real. Make it different from the last image:

Jupiter Exchange hits pause on DAO voting until 2026 to accelerate DeFi dominance

06/20/2025
16 billion login credentials leaked in unprecedented breach—Apple, Google at risk

16 billion login credentials leaked in unprecedented breach—Apple, Google at risk

06/20/2025
Exposed: How North Korean hackers crushed crypto defences with strategic PylangGhost scam

Exposed: How North Korean hackers crushed crypto defences with strategic PylangGhost scam

06/20/2025
  • Trending
  • Comments
  • Latest
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Bitcoin ETF Flows surge as Fidelity, ARK & BlackRock attract $667M in one day

Bitcoin ETF Flows surge as Fidelity, ARK & BlackRock attract $667M in one day

05/20/2025
Just In: LastPass Hackers Strike Again Ahead of Christmas, Losses Near $45M

New York Post X account hacked in high-profile breach, triggers cybersecurity scrutiny

05/05/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2

Hello world!

1
Peter Brandt Warns of Major Ethereum (ETH) Crash to $1,651 in Latest Ethereum (ETH) Price Prediction

Ethereum Merge Fades: Supply Surge May Lead to Price Dip, Expert Warns, as ETF Hype Loses Steam

1
create a landscape image illustrating this with pictures, not texts. Use a real human figure and make the entire composition look real. Make it different from the last image:

Jupiter Exchange hits pause on DAO voting until 2026 to accelerate DeFi dominance

06/20/2025
16 billion login credentials leaked in unprecedented breach—Apple, Google at risk

16 billion login credentials leaked in unprecedented breach—Apple, Google at risk

06/20/2025
Exposed: How North Korean hackers crushed crypto defences with strategic PylangGhost scam

Exposed: How North Korean hackers crushed crypto defences with strategic PylangGhost scam

06/20/2025
Friday, June 20, 2025
  • Login
The Bit Gazette
  • Home
  • News
  • Crypto
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored Articles
  • Contact
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home News

Exposed: How North Korean hackers crushed crypto defences with strategic PylangGhost scam

North Korean hackers are hijacking Crypto with PylangGhost

by Davidson Okechukwu
4 hours ago
in News
Reading Time: 3 mins read
0
Exposed: How North Korean hackers crushed crypto defences with strategic PylangGhost scam

Exposed: How North Korean hackers crushed crypto defences with strategic PylangGhost scam

Share on FacebookShare on Twitter

North Korean Hackers are unleashing a new wave of crypto-targeted cyberattacks using a powerful Trojan called PylangGhost.

North Korean Hackers have escalated their attacks on the crypto industry with a powerful new threat—PylangGhost, a Python-based Trojan that’s deceiving blockchain professionals through fake job interviews.

Masquerading as recruiters from major firms like Coinbase and Robinhood, these state-backed cybercriminals are now exploiting human trust to steal digital fortunes.

This alarming new campaign demonstrates how North Korean Hackers are evolving their playbook, pivoting from brute-force intrusion to masterful social engineering.

The malware, dubbed PylangGhost, was uncovered by cybersecurity experts at Cisco Talos and linked to the “Famous Chollima” threat group, a known arm of North Korea’s state-sponsored Lazarus Group.

PylangGhost Trojan: A New Chapter in Crypto Espionage

At the heart of the attack is a carefully orchestrated scam: North Korean Hackers impersonate hiring managers from Coinbase, Uniswap, and Robinhood, luring skilled professionals through fake job listings.

“Once inside the fake interview ecosystem, the malware does the rest,” said Vanja Svajcer, a threat researcher at Cisco Talos.

“It mimics the entire hiring process, from skill assessments to video interviews, all designed to coax victims into downloading malicious files.”

Source: Talos Intelligence
Source: Talos Intelligence

Targets are invited to React-based fake hiring portals that mimic real corporate testing platforms.

These sites are packed with technical questions to legitimize the process—then bait victims with instructions to install bogus video drivers.

When unsuspecting users comply, PylangGhost unpacks. This modular malware does more than scrape credentials—it hijacks system access, runs OS shell commands, and compromises crypto wallets like MetaMask, Phantom, Bitski, and TronLink.

A Deeply Engineered RAT

PylangGhost is no ordinary Trojan. Once deployed, it disguises its presence under filenames like nvidia.py, builds persistence via registry edits and communicates with remote command-and-control servers using unique system GUIDs. According to Cisco’s findings, it can:

  • Exfiltrate browser-stored passwords

  • Harvest session cookies and authentication tokens

  • Target over 80 browser extensions and wallet plugins

  • Deploy file upload/download modules and full shell access

“The technical sophistication of this tool indicates deep state-level support and planning,” noted Joe Slowik, threat intelligence principal at Huntress.

While global in scope, this wave of attacks appears to focus on crypto developers and engineers in India, a hub for blockchain innovation.

Using geo-targeting and browser fingerprinting, North Korean Hackers tailor each attack to maximize effectiveness.

Once infected, victims often remain unaware for weeks, during which time their wallets and credentials are silently siphoned away.

Exchanges Strike Back

Major exchanges are fighting back. Kraken recently intercepted a North Korean mole posing as a job applicant.

“Our red team flagged unusual metadata in the applicant’s documents,” Kraken CISO Nick Percoco revealed. “This gave us a window into the Lazarus playbook.”

BitMEX also conducted a counterintelligence sweep that exposed IP ranges linked to the group, revealing fragmented structures and regional command nodes.

With North Korean Hackers refining their methods, the crypto world must brace for a long-term battle.

Fake recruiters, Trojanized interviews, and data exfiltration are no longer fringe tactics—they’re the new norm in this high-stakes cyberwar.

For now, the best defense is awareness. As Svajcer of Cisco concluded, “If a recruiter ever asks you to install software, you’re not getting hired—you’re getting hacked.”

Tags: altcoinsbitcoin regulationCrypto cyber-warNorth Korean HacksPylangGhost
Share197Tweet123
Davidson Okechukwu

Davidson Okechukwu

Davidson Okechukwu is a passionate crypto journalist/writer and Web3 enthusiast, focusing on blockchain innovation, deFI, NFT ecosystems, and the societal impact of decentralized systems. His engaging style bridges the gap between technology and everyday understanding with a degree in Computer Science and various professional certifications from prestigious institutions. With over four years of experience in the crypto and DeFi space, Davidson combines his technical knowledge with a keen understanding of market dynamics. In addition to his work in cryptocurrency, he is a dedicated realtor and web management professional.

  • Trending
  • Comments
  • Latest
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Bitcoin ETF Flows surge as Fidelity, ARK & BlackRock attract $667M in one day

Bitcoin ETF Flows surge as Fidelity, ARK & BlackRock attract $667M in one day

05/20/2025
Just In: LastPass Hackers Strike Again Ahead of Christmas, Losses Near $45M

New York Post X account hacked in high-profile breach, triggers cybersecurity scrutiny

05/05/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2

Hello world!

1
Peter Brandt Warns of Major Ethereum (ETH) Crash to $1,651 in Latest Ethereum (ETH) Price Prediction

Ethereum Merge Fades: Supply Surge May Lead to Price Dip, Expert Warns, as ETF Hype Loses Steam

1
create a landscape image illustrating this with pictures, not texts. Use a real human figure and make the entire composition look real. Make it different from the last image:

Jupiter Exchange hits pause on DAO voting until 2026 to accelerate DeFi dominance

06/20/2025
16 billion login credentials leaked in unprecedented breach—Apple, Google at risk

16 billion login credentials leaked in unprecedented breach—Apple, Google at risk

06/20/2025
Exposed: How North Korean hackers crushed crypto defences with strategic PylangGhost scam

Exposed: How North Korean hackers crushed crypto defences with strategic PylangGhost scam

06/20/2025
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Crypto
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored Articles
  • Contact

Copyright © 2025 - The Bit Gazette.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?