Place your ads here email us at info@blockchain.news
NEW
North Korean Hackers Target Coinbase and Uniswap Job Applicants With New PylangGhost Malware | Flash News Detail | Blockchain.News
Latest Update
6/28/2025 6:44:00 PM

North Korean Hackers Target Coinbase and Uniswap Job Applicants With New PylangGhost Malware

North Korean Hackers Target Coinbase and Uniswap Job Applicants With New PylangGhost Malware

According to phantom, a North Korean hacking group known as Famous Chollima is actively targeting cryptocurrency professionals with a new Python-based malware named PylangGhost. The attack vector involves impersonating top crypto firms like Coinbase, Robinhood, and Uniswap through sophisticated fake career websites, as detailed in a report by Cisco Talos. Job applicants, particularly software engineers and designers in India, are lured into a fake skills test that tricks them into running a command to install the malware. For traders, the primary risk is the malware's ability to steal critical data from over 80 browser extensions, including popular wallets like MetaMask, Phantom, and TronLink, as well as password managers like 1Password. This could lead to the direct theft of user funds, compromising individual accounts and potentially impacting the security and reputation of the targeted platforms. The malware grants attackers full remote control over infected Windows machines, posing a significant threat to the assets held by employees and users of major crypto companies.

Source

Analysis

The cryptocurrency industry is once again in the crosshairs of sophisticated, state-sponsored cyber attacks. Researchers at Cisco Talos have uncovered a new campaign by a North Korean hacking collective, known as Famous Chollima, targeting individuals within the crypto space. This latest threat employs a novel Python-based malware, dubbed PylangGhost, which is cleverly disguised within a fake job application process. The attackers impersonate major crypto firms like Coinbase, Robinhood, and Uniswap, creating highly convincing fake careers websites to lure in unsuspecting software engineers, marketers, and other professionals. This type of persistent threat creates an undercurrent of risk that traders must factor into their long-term market sentiment, as successful breaches could lead to stolen funds and severe reputational damage for compromised projects.



The Anatomy of the PylangGhost Attack


The attack vector is a multi-stage process designed to exploit user trust. Candidates are drawn to these polished, fake job portals and prompted to complete a staged "skill test." After answering technical questions, the victim is instructed to install what appears to be a necessary video driver by pasting a command into their system's terminal. This action, however, stealthily downloads and executes the PylangGhost remote access trojan (RAT). According to the Cisco Talos report, the malware is specifically engineered for Windows systems, a strategic shift from the group's previous GolangGhost RAT that targeted macOS users. The malware payload is extensive, capable of establishing persistence, fingerprinting the system, and enabling full remote control. Critically for crypto traders and users, it is designed to steal sensitive data from over 80 browser extensions, including widely used wallets like MetaMask, Phantom, and TronLink, as well as password managers like 1Password. This highlights a significant operational security risk that goes beyond simple price volatility.



Market Resilience in the Face of Threats


Despite the gravity of these security threats, the broader crypto market has demonstrated notable resilience. Analyzing the price action for key assets like Ethereum (ETH) reveals a market currently focused on short-term technicals. The ETH/USDT pair is trading around $2,444.57, posting a modest 24-hour gain of 0.745%. The immediate trading range has been established between a low of $2,421.57 and a high of $2,447.65. These levels now serve as crucial near-term support and resistance for intraday traders. A decisive break above $2,450 could signal further bullish momentum, while a drop below the $2,420 support might invite selling pressure. Furthermore, the ETH/BTC pair shows a 0.531% increase to 0.02274, indicating that Ethereum is currently outperforming Bitcoin, a potentially bullish sign for the altcoin market. This price strength suggests that while security news can create FUD (Fear, Uncertainty, and Doubt), active market participants are still identifying and acting on trading opportunities based on chart patterns and order flow.



Chainlink (LINK) Shows Notable Strength


Another asset displaying strong performance is Chainlink (LINK). The LINK/USDT pair has rallied 1.897% to trade at $13.43, pushing against its 24-hour high of $13.45. The daily low of $12.99 has acted as a solid support base, from which buyers have stepped in. The trading volume for this pair is substantial at over 5,700 USDT, indicating genuine interest. Even more telling is the LINK/BTC pair, which has climbed 1.017% to 0.000149 BTC. The volume on this specific pair is exceptionally high at over 2,562 BTC, suggesting a significant rotation of capital from Bitcoin into Chainlink. Traders may be interpreting the fundamental value of Chainlink's oracle services as a safe haven within the crypto ecosystem, especially when security is a top concern. The ability for smart contracts to securely access off-chain data is a cornerstone of DeFi, and continued investment in LINK, even amidst hacking fears, underscores this long-term value proposition. For traders, the key levels to watch are the resistance at $13.45 and support near the $13.00 psychological level. A sustained move above the current high could open the door to further upside, targeting the $14.00 mark.

Phantom

@phantom

The friendly crypto wallet built for DeFi & NFTs.

Place your ads here email us at info@blockchain.news