Knowledge

Researchers Reveal Alarming North Korean ClickFake Attack on Web3 Talent

Time:2010-12-5 17:23:32  Author:Leisure   Source:Focus  Views:  Comments:0
Summary:**Researchers Reveal Alarming North Korean ClickFake Attack on Web3 Talent** *Summary: A newly unco



referrerpolicy="no-referrer"
style="max-width:100%;height:auto;display:block;margin:0 auto;">


**Researchers Reveal Alarming North Korean ClickFake Attack on Web3 Talent**
*Summary: A newly uncovered operation by the North Korean hacking group Famous Chollima used ClickFix‑style lures to compromise crypto‑focused professionals, delivering tailored Windows and macOS trojans that steal credentials and private keys.*

### Introduction
Cybersecurity analysts at a joint task force of industry firms and government agencies disclosed on Tuesday that a sophisticated phishing campaign has been targeting developers, auditors, and community managers working in the Web3 space. The attackers, identified as the notorious Famous Chollima unit, crafted fake job offers and collaboration invitations that appeared to come from legitimate blockchain projects. When recipients clicked the embedded links, a malicious payload was dropped onto their workstations, initiating a multi‑stage infection chain designed to exfiltrate sensitive data.

### Key Developments
The campaign, dubbed “ClickFake” by researchers, relied on two primary lures: a spoofed LinkedIn message promising a senior smart‑contract auditor role and a counterfeit Discord announcement advertising a bounty program for a new DeFi protocol. Both messages contained a shortened URL that redirected to a hosting server controlled by the threat actors. Upon visiting the page, victims were prompted to download a ZIP file labeled “Onboarding_Kit.zip.” Inside, a signed executable for Windows or a notarized app bundle for macOS executed a dropper that installed a remote‑access trojan (RAT). The RAT communicated with command‑and‑control servers using encrypted DNS queries, harvested wallet files, browser credentials, and SSH keys, and then uploaded the stolen material to a compromised cloud storage bucket. Telemetry from endpoint protection platforms showed over 1,200 unique infection attempts across North America, Europe, and Southeast Asia within a three‑week window.

### Industry Analysis
Security experts note that the ClickFake operation reflects a shift in state‑sponsored tactics toward highly personalized social engineering
copyright © 2026 powered by Urban Hub   sitemap