← Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)1 decision on this page
Audit log
Every state-changing event for Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-04 12:17:37ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
2Qzdbuu1pjwt…hRMrLitBsha256 → base58
verifying row…canonical bytes (27507 B) ▸
{"actor":"system:backfill","investigation_id":"dd4506df-f53a-4fb4-8a37-e2a89d110810","kind":"publish","page_slug":"famous-chollima-clickfake-interview-campaign-pylangghost-golangghost","published_at":"2026-08-04T12:17:37.269Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)","sections":[{"content":"The ClickFake Interview campaign is attributed with high confidence to Famous Chollima, also tracked as Wagemole, Storm-1877, UNC5267, NICKEL TAPESTRY, Tenacious Pungsan, Void Dokkaebi, Contagious Interview, PurpleBravo, and DEV#POPPER by various security vendors. CrowdStrike designates the group Famous Chollima and states it has been active since at least 2018. Sekoia and Cisco Talos place attribution within the 3rd Department of the Reconnaissance General Bureau (RGB) of the Democratic People's Republic of Korea, situating the group under the broader Lazarus Group organizational umbrella. Some vendors draw a further distinction, linking certain Famous Chollima sub-clusters to BlueNoroff or APT38, which are financial-theft-focused units historically responsible for bank heist operations. The group's primary motivation is financial: illicitly obtaining crypto assets and fiat income to fund DPRK state priorities. Its known malware families span BeaverTail, InvisibleFerret, OtterCookie, GolangGhost, FrostyFerret, and the 2025-discovered PylangGhost.","heading":"Attribution and Threat Actor Background","severity":"critical","sources":[{"credibility":2,"name":"CrowdStrike Famous Chollima Adversary Profile","type":"research","url":"https://www.crowdstrike.com/en-us/adversaries/famous-chollima/"},{"credibility":2,"name":"Sekoia ClickFake Interview Campaign by Lazarus","type":"research","url":"https://www.sekoia.com/blog/clickfake-interview-campaign-by-lazarus"},{"credibility":2,"name":"Cisco Talos: Famous Chollima deploying Python version of GolangGhost RAT","type":"research","url":"https://blog.talosintelligence.com/python-version-of-golangghost-rat/"}]},{"content":"The ClickFake Interview campaign is assessed by Sekoia as a direct evolution of the Contagious Interview campaign first documented by Palo Alto Networks in November 2023, though the underlying activity is believed to date to at least December 2022. The 2025 iteration was codenamed ClickFake Interview by Sekoia to distinguish its adoption of the ClickFix social engineering vector — a technique in which victims are induced to paste and execute malicious terminal commands under the guise of fixing a technical error. Cisco Talos published a separate analysis in 2025 identifying PylangGhost, a Python-based counterpart to the previously documented Go-based GolangGhost RAT, confirming the campaign was ongoing and expanding its platform-specific payloads. SOCRadar's Threat Research Unit published a further update on July 20, 2026 documenting new infrastructure and continued active operations. The campaign represents a deliberate tactical shift: whereas Contagious Interview primarily targeted software developers via GitHub-hosted malicious repositories, ClickFake Interview widens the targeting pool to include non-technical cryptocurrency industry roles such as marketing managers, business development staff, and asset managers — profiles with access to company funds and internal systems but less likely to scrutinize malicious payloads.","heading":"Campaign Overview and Evolution","severity":"critical","sources":[{"credibility":2,"name":"Sekoia: From Contagious to ClickFake Interview (TLP:CLEAR PDF)","type":"research","url":"https://blog.sekoia.io/wp-content/uploads/2025/05/From-contagious-to-clickfake-interview-sekoia.io-march-2025-tlp-clear.pdf"},{"credibility":2,"name":"The Hacker News: Lazarus Group Targets Job Seekers With ClickFix Tactic","type":"news_article","url":"https://thehackernews.com/2025/04/lazarus-group-targets-job-seekers-with.html"},{"credibility":2,"name":"SOCRadar: DPRK's Famous Chollima Deploys RATs Through ClickFake Job Interviews","type":"research","url":"https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/"},{"credibility":2,"name":"Infosecurity Magazine: Researchers Uncover North Korean ClickFake Campaign Targeting Web3","type":"news_article","url":"https://www.infosecurity-magazine.com/news/north-korean-clickfake-campaign/"}]},{"content":"The operation begins with operators posing as recruiters on LinkedIn, X (formerly Twitter), Telegram, Discord, and email. Attackers either create fictitious companies or impersonate well-known cryptocurrency firms including Coinbase, KuCoin, Kraken, Bybit, Robinhood, Tether, Circle, Securitize, BlockFi, Uniswap, Archblock, and Parallel Studios. Targets are offered lucrative positions and invited to complete a skills assessment on attacker-controlled web portals built in ReactJS. These portals incorporate psychological pressure tactics including countdown timers, tab-switching warnings, video recording interfaces, and geolocation-based filtering and CAPTCHA mechanisms to obstruct automated security scanning. At a critical point in the assessment, the platform simulates a camera or microphone access failure and prompts the candidate to paste a diagnostic command into their system terminal — the ClickFix technique. On Windows, the command initiates a curl or PowerShell Invoke-WebRequest download of a ZIP archive containing PylangGhost components and a disguised Python interpreter (nvidia.py). The archive extracts via PowerShell, a VBS script launches the RAT, and persistence is established via a registry key at HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run. On macOS, a curl command downloads a bash script which fetches an architecture-specific ZIP, executes the FrostyFerret credential stealer (impersonating a Chrome update dialog to harvest the system password and exfiltrate it to Dropbox), then creates a LaunchAgent plist for persistence and launches GolangGhost. Attackers register their assessment domains predominantly through Hostinger and NameCheap, prioritizing volume and speed over operational security longevity.","heading":"Attack Chain and Social Engineering Method","severity":"critical","sources":[{"credibility":2,"name":"Sekoia: From Contagious to ClickFake Interview (TLP:CLEAR PDF)","type":"research","url":"https://blog.sekoia.io/wp-content/uploads/2025/05/From-contagious-to-clickfake-interview-sekoia.io-march-2025-tlp-clear.pdf"},{"credibility":2,"name":"Cisco Talos: Famous Chollima deploying Python version of GolangGhost RAT","type":"research","url":"https://blog.talosintelligence.com/python-version-of-golangghost-rat/"},{"credibility":2,"name":"Cryptika: New ClickFake Interview Attack Using ClickFix Technique","type":"news_article","url":"https://www.cryptika.com/new-clickfake-interview-attack-using-clickfix-technique-to-deliver-golangghost-malware/"}]},{"content":"PylangGhost is a Python-based remote access trojan (RAT) first identified by Cisco Talos in May 2025 and documented as exclusive to Famous Chollima. It is structurally equivalent in capability to GolangGhost but targets Windows systems. The malware is composed of six Python modules: a main launcher (nvidia.py), a configuration holder (config.py), an archive helper, a command launcher (command.py), a C2 communications module (api.py), and a dedicated data stealer (auto.py). Communication with command-and-control infrastructure uses RC4-encrypted HTTP packets; the malware generates a unique system GUID to register the victim with the C2 server. In newer variants, Cisco Talos documented the attackers compiling PylangGhost scripts into native Windows DLLs using Nuitka, an approach that converts Python to C++ then native binaries, substantially complicating signature-based detection and static analysis. PylangGhost's stealer module targets over 80 browser extensions, including cryptocurrency wallets (MetaMask, Phantom, TronLink) and commercial password managers (1Password, NordPass). Observed C2 server IPs documented by Cisco Talos include 31.57.243.29:8080, 154.58.204.15:8080, and others. Staging download hostnames included quickcamfix.online and nvidia-drive.cloud. Cisco Talos documented 25 malware SHA256 hashes across PylangGhost modules and 23 fake job interview domains. One confirmed sample hash: c2137cd870de0af6662f56c97d27b86004f47b866ab27190a97bde7518a9ac1b.","heading":"PylangGhost Malware: Technical Capabilities","severity":"critical","sources":[{"credibility":2,"name":"Cisco Talos: Famous Chollima deploying Python version of GolangGhost RAT","type":"research","url":"https://blog.talosintelligence.com/python-version-of-golangghost-rat/"},{"credibility":2,"name":"PolySwarm: Famous Chollima's PylangGhost","type":"research","url":"https://blog.polyswarm.io/famous-chollimas-pylangghost"},{"credibility":2,"name":"Anvilogic: North Korean Group Deploys PylangGhost RAT","type":"research","url":"https://www.anvilogic.com/threat-reports/pylangghost-job-scam-rat"},{"credibility":2,"name":"Crypto.news: Cisco Talos New North Korean Threat PylangGhost","type":"news_article","url":"https://crypto.news/cisco-talos-new-north-korean-threat-pylangghost-targets-crypto-workers-through-fake-job-sites/"}]},{"content":"GolangGhost is a Go-based remote access trojan targeting macOS systems, documented initially by Sekoia in March 2025 and subsequently analyzed by multiple vendors. It is delivered on macOS as the final stage following FrostyFerret's system password theft. GolangGhost version 2.0.1 was identified in analyzed samples. The malware establishes persistence via a LaunchAgent plist and immediately contacts hardcoded C2 endpoints over TLS-wrapped WebSockets, exporting a full process inventory and OS-level metadata within seconds of execution. C2 communication uses RC4 encryption with 128-byte dynamic keys. Capabilities include remote command execution, file upload and download, shell command execution, Chrome browser data theft (cookies, saved passwords, and macOS Keychain secrets), and MetaMask wallet permission hijacking. Dynamic module loading via base64-encoded gRPC is used to extend capabilities post-infection. On Windows, a parallel attack chain delivers GolangGhost via NodeJS downloader (nvidia.js), a VBS script, and a batch file (go_batch.bat), establishing persistence via HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run with a randomized key matching a 'SysDrvX %RAND%' pattern. Observed GolangGhost C2 IPs include 38.134.148.218:8080, 154.62.226.22:8080, and 72.5.42.93:8080. Staging C2 domains include api.smartdriverfix.cloud, api.webcamdrivers.cloud, and api.nvidia-release.org. Malpedia maintains a dedicated GolangGhost malware family entry.","heading":"GolangGhost Malware: Technical Capabilities","severity":"critical","sources":[{"credibility":2,"name":"Sekoia: From Contagious to ClickFake Interview (TLP:CLEAR PDF)","type":"research","url":"https://blog.sekoia.io/wp-content/uploads/2025/05/From-contagious-to-clickfake-interview-sekoia.io-march-2025-tlp-clear.pdf"},{"credibility":2,"name":"Malpedia: GolangGhost Malware Family","type":"research","url":"https://malpedia.caad.fkie.fraunhofer.de/details/win.golangghost"},{"credibility":2,"name":"CyberSecurityNews: GolangGhost Steals Chrome Secrets From macOS Keychain","type":"news_article","url":"https://cybersecuritynews.com/golangghost-steals-chrome-secrets/"},{"credibility":2,"name":"Cryptika: New ClickFake Interview Attack Using ClickFix Technique","type":"research","url":"https://www.cryptika.com/new-clickfake-interview-attack-using-clickfix-technique-to-deliver-golangghost-malware/"}]},{"content":"The ClickFake Interview campaign specifically targets cryptocurrency and Web3 industry professionals. Sekoia's March 2025 report identified at least 14 cryptocurrency companies whose identities are impersonated in fake recruitment lures, predominantly centralized finance (CeFi) platforms including Coinbase, KuCoin, Kraken, Bybit, Robinhood, Tether, Circle, Securitize, and BlockFi, with at least one decentralized finance platform (Archblock). A notable strategic evolution documented by Sekoia is the deliberate targeting of non-technical roles — marketing managers, business development representatives, and asset managers — in contrast to prior campaigns that primarily targeted software developers. This shift suggests the actors are pursuing indirect access vectors to company financial systems through employees who may be less likely to scrutinize unusual technical instructions. Cisco Talos telemetry indicates a limited observed impact with victims predominantly concentrated in India, suggesting targeted rather than mass-scale operations. No Cisco customers were confirmed among affected parties in Talos's reporting period. SOCRadar assessed that actors additionally seek indirect access to pivot toward company funds.","heading":"Targeted Sectors and Victim Profile","severity":"high","sources":[{"credibility":2,"name":"Sekoia: ClickFake Interview Campaign by Lazarus","type":"research","url":"https://www.sekoia.com/blog/clickfake-interview-campaign-by-lazarus"},{"credibility":2,"name":"Cisco Talos: Famous Chollima deploying Python version of GolangGhost RAT","type":"research","url":"https://blog.talosintelligence.com/python-version-of-golangghost-rat/"},{"credibility":2,"name":"Infosecurity Magazine: Researchers Uncover North Korean ClickFake Campaign Targeting Web3","type":"news_article","url":"https://www.infosecurity-magazine.com/news/north-korean-clickfake-campaign/"}]},{"content":"The ClickFake Interview campaign operates within a broader North Korean state strategy of using cryptocurrency theft as a structural revenue source. The FBI confirmed via an IC3 public service announcement dated February 26, 2025 that the Lazarus Group (designated TraderTraitor by the FBI) was responsible for stealing approximately $1.5 billion USD from Bybit on or about February 21, 2025 — the largest crypto theft on record. DPRK-linked actors stole an estimated $2.02 billion in cryptocurrency in 2025 alone, a 51% year-on-year increase, pushing their alleged all-time cumulative total to approximately $6.75 billion. The Bybit theft involved compromise of a Safe{Wallet} developer machine to authorize a malicious transaction during a cold-to-hot wallet transfer. The FBI urged private sector entities including RPC node operators, exchanges, and DeFi services to block transactions associated with 52 Ethereum wallet addresses linked to the theft. The ClickFake Interview campaign's credential theft focus — particularly targeting MetaMask, Phantom, and TronLink wallet extensions — is consistent with this broader state-directed financial exfiltration strategy.","heading":"Broader DPRK Crypto Theft Context","severity":"critical","sources":[{"credibility":1,"name":"FBI IC3 PSA: North Korea Responsible for $1.5 Billion Bybit Hack","type":"regulatory","url":"https://www.ic3.gov/psa/2025/psa250226"},{"credibility":2,"name":"CSIS: The ByBit Heist and the Future of U.S. Crypto Regulation","type":"research","url":"https://www.csis.org/analysis/bybit-heist-and-future-us-crypto-regulation"},{"credibility":2,"name":"Picus Security: FBI Confirms North Korean Lazarus Group Behind $1.5 Billion Bybit Crypto Heist","type":"news_article","url":"https://www.picussecurity.com/resource/blog/fbi-north-korean-lazarus-group-bybit-crypto-heist"}]},{"content":"The campaign's infrastructure is characterized by rapid domain registration through budget registrars Hostinger and NameCheap, prioritizing operational speed over infrastructure longevity. Known staging download hostnames include quickcamfix.online and nvidia-drive.cloud. Fake interview assessment domains impersonate legitimate recruitment and crypto company branding; at least 23 such domains were identified by Cisco Talos. Known C2 server IPs include 31.57.243.29:8080 and 154.58.204.15:8080 (PylangGhost), and 38.134.148.218:8080, 154.62.226.22:8080, and 72.5.42.93:8080 (GolangGhost). Staging C2 hostnames include api.smartdriverfix.cloud, api.webcamdrivers.cloud, and api.nvidia-release.org. The domain talentacq.pro was observed in one active campaign, registered September 23 and weaponized less than two weeks later. A Sigma detection rule identifies the attack pattern via temporal sequencing of curl download, PowerShell extraction, and wscript execution within a two-minute window sharing the same hostname and parent process ID. Windows RunMRU registry keys showing cmd.exe entries represent an additional detection artifact. GolangGhost persistence entries match a SysDrvX %RAND% pattern in the Windows registry.","heading":"Infrastructure and Indicators of Compromise","severity":"high","sources":[{"credibility":2,"name":"Cisco Talos: Famous Chollima deploying Python version of GolangGhost RAT","type":"research","url":"https://blog.talosintelligence.com/python-version-of-golangghost-rat/"},{"credibility":2,"name":"Sekoia: From Contagious to ClickFake Interview (TLP:CLEAR PDF)","type":"research","url":"https://blog.sekoia.io/wp-content/uploads/2025/05/From-contagious-to-clickfake-interview-sekoia.io-march-2025-tlp-clear.pdf"},{"credibility":2,"name":"Cryptika: New ClickFake Interview Attack Using ClickFix Technique","type":"research","url":"https://www.cryptika.com/new-clickfake-interview-attack-using-clickfix-technique-to-deliver-golangghost-malware/"}]},{"content":"Security researchers and the FBI have published defensive guidance relevant to this campaign. Job seekers in the cryptocurrency and Web3 space should treat any recruitment process that instructs them to paste commands into a terminal as a strong indicator of compromise. Organizations should implement endpoint detection rules covering the temporal sequencing of curl, PowerShell, and wscript execution chains as documented in Sekoia's Sigma rule. macOS environments should monitor for unexpected LaunchAgent plist creation and outbound WebSocket connections to unfamiliar domains. Browser extension security policies should be reviewed, with particular attention to limiting extensions with broad wallet access. The FBI's February 2025 IC3 PSA recommended that exchanges, bridges, DeFi services, and blockchain analytics firms block transactions associated with known TraderTraitor wallet addresses. Microsoft published guidance on the Contagious Interview malware family in March 2026. OSINT-based threat intelligence reports recommend verifying recruiter identities through official company channels before engaging with any technical assessment, particularly those involving camera or device permissions.","heading":"Defensive Recommendations","severity":"medium","sources":[{"credibility":1,"name":"FBI IC3 PSA: North Korea Responsible for $1.5 Billion Bybit Hack","type":"regulatory","url":"https://www.ic3.gov/psa/2025/psa250226"},{"credibility":2,"name":"Microsoft Security Blog: Contagious Interview Malware Delivered Through Fake Developer Job Interviews","type":"research","url":"https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/"},{"credibility":2,"name":"Sekoia: From Contagious to ClickFake Interview (TLP:CLEAR PDF)","type":"research","url":"https://blog.sekoia.io/wp-content/uploads/2025/05/From-contagious-to-clickfake-interview-sekoia.io-march-2025-tlp-clear.pdf"}]}],"sources_used":[{"credibility":2,"name":"Cisco Talos: Famous Chollima deploying Python version of GolangGhost RAT","type":"research","url":"https://blog.talosintelligence.com/python-version-of-golangghost-rat/"},{"credibility":2,"name":"SOCRadar: DPRK's Famous Chollima Deploys RATs Through ClickFake Job Interviews","type":"research","url":"https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/"},{"credibility":2,"name":"Sekoia: ClickFake Interview Campaign by Lazarus","type":"research","url":"https://www.sekoia.com/blog/clickfake-interview-campaign-by-lazarus"},{"credibility":2,"name":"Sekoia: From Contagious to ClickFake Interview (TLP:CLEAR PDF)","type":"research","url":"https://blog.sekoia.io/wp-content/uploads/2025/05/From-contagious-to-clickfake-interview-sekoia.io-march-2025-tlp-clear.pdf"},{"credibility":2,"name":"The Hacker News: Lazarus Group Targets Job Seekers With ClickFix Tactic","type":"news_article","url":"https://thehackernews.com/2025/04/lazarus-group-targets-job-seekers-with.html"},{"credibility":1,"name":"FBI IC3 PSA: North Korea Responsible for $1.5 Billion Bybit Hack","type":"regulatory","url":"https://www.ic3.gov/psa/2025/psa250226"},{"credibility":2,"name":"Infosecurity Magazine: Researchers Uncover North Korean ClickFake Campaign Targeting Web3","type":"news_article","url":"https://www.infosecurity-magazine.com/news/north-korean-clickfake-campaign/"},{"credibility":2,"name":"GBHackers: North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs","type":"news_article","url":"https://gbhackers.com/north-korean-hackers-use-fake-job-interviews/"},{"credibility":2,"name":"PolySwarm: Famous Chollima's PylangGhost","type":"research","url":"https://blog.polyswarm.io/famous-chollimas-pylangghost"},{"credibility":2,"name":"CrowdStrike Famous Chollima Adversary Profile","type":"research","url":"https://www.crowdstrike.com/en-us/adversaries/famous-chollima/"},{"credibility":2,"name":"Malpedia: GolangGhost Malware Family","type":"research","url":"https://malpedia.caad.fkie.fraunhofer.de/details/win.golangghost"},{"credibility":2,"name":"Microsoft Security Blog: Contagious Interview Malware Delivered Through Fake Developer Job Interviews","type":"research","url":"https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/"},{"credibility":2,"name":"CyberSecurityNews: GolangGhost Steals Chrome Secrets From macOS Keychain","type":"news_article","url":"https://cybersecuritynews.com/golangghost-steals-chrome-secrets/"},{"credibility":2,"name":"Cryptika: New ClickFake Interview Attack Using ClickFix Technique","type":"research","url":"https://www.cryptika.com/new-clickfake-interview-attack-using-clickfix-technique-to-deliver-golangghost-malware/"},{"credibility":2,"name":"Anvilogic: North Korean Group Deploys PylangGhost RAT","type":"research","url":"https://www.anvilogic.com/threat-reports/pylangghost-job-scam-rat"},{"credibility":2,"name":"Crypto.news: Cisco Talos New North Korean Threat PylangGhost","type":"news_article","url":"https://crypto.news/cisco-talos-new-north-korean-threat-pylangghost-targets-crypto-workers-through-fake-job-sites/"},{"credibility":2,"name":"CSIS: The ByBit Heist and the Future of U.S. Crypto Regulation","type":"research","url":"https://www.csis.org/analysis/bybit-heist-and-future-us-crypto-regulation"},{"credibility":2,"name":"Picus Security: FBI Confirms North Korean Lazarus Group Behind Bybit Crypto Heist","type":"news_article","url":"https://www.picussecurity.com/resource/blog/fbi-north-korean-lazarus-group-bybit-crypto-heist"}],"summary":"The ClickFake Interview campaign is an active cyberespionage operation attributed with high confidence to Famous Chollima, a North Korean state-sponsored threat actor linked to the Reconnaissance General Bureau and the broader Lazarus Group umbrella. Targets are cryptocurrency and Web3 professionals lured via fake job recruitment on LinkedIn, Telegram, and Discord, then induced through a ClickFix social engineering trick to execute terminal commands that install the PylangGhost (Windows) or GolangGhost (macOS) remote access trojans, which steal credentials from over 80 browser extensions including cryptocurrency wallets and password managers. The campaign, documented since at least mid-2024 in its current form, evolved from the earlier Contagious Interview / DEV#POPPER lineage and represents a continuing North Korean strategy of using employment lures to harvest crypto assets.","timeline":[{"date":"2022-12-01","event":"Contagious Interview campaign begins, targeting software developers via fake GitHub-hosted coding assessments. Attributed to Famous Chollima / Lazarus Group.","source":"Sekoia Research / Palo Alto Networks","source_url":"https://blog.sekoia.io/wp-content/uploads/2025/05/From-contagious-to-clickfake-interview-sekoia.io-march-2025-tlp-clear.pdf"},{"date":"2023-11-01","event":"Palo Alto Networks publicly documents the Contagious Interview campaign for the first time.","source":"The Hacker News","source_url":"https://thehackernews.com/2025/04/lazarus-group-targets-job-seekers-with.html"},{"date":"2024-06-01","event":"Campaign evolves; GolangGhost backdoor and FrostyFerret macOS stealer first observed in ongoing fake interview operations.","source":"Cisco Talos","source_url":"https://blog.talosintelligence.com/python-version-of-golangghost-rat/"},{"date":"2025-02-21","event":"Lazarus Group (TraderTraitor) steals approximately $1.5 billion USD from Bybit via compromise of Safe{Wallet} developer infrastructure — the largest crypto theft on record.","source":"FBI IC3 PSA","source_url":"https://www.ic3.gov/psa/2025/psa250226"},{"date":"2025-02-26","event":"FBI IC3 releases public service announcement attributing the Bybit theft to North Korea's Lazarus Group (TraderTraitor) and publishing 52 associated Ethereum wallet addresses.","source":"FBI Internet Crime Complaint Center","source_url":"https://www.ic3.gov/psa/2025/psa250226"},{"date":"2025-03-21","event":"Sekoia distributes private FLINT report codenaming the evolved campaign ClickFake Interview, documenting GolangGhost, FrostyFerret, and the shift to ClickFix social engineering and CeFi targeting.","source":"Sekoia","source_url":"https://www.sekoia.com/blog/clickfake-interview-campaign-by-lazarus"},{"date":"2025-04-01","event":"Sekoia publicly releases ClickFake Interview research; The Hacker News and Infosecurity Magazine cover findings. Campaign linked to 40+ companion domains registered in April 2025.","source":"The Hacker News","source_url":"https://thehackernews.com/2025/04/lazarus-group-targets-job-seekers-with.html"},{"date":"2025-05-01","event":"Cisco Talos identifies PylangGhost, a Python-based Windows RAT functionally equivalent to GolangGhost, marking a new malware family exclusive to Famous Chollima in the ClickFake campaign.","source":"Cisco Talos","source_url":"https://blog.talosintelligence.com/python-version-of-golangghost-rat/"},{"date":"2026-03-11","event":"Microsoft Security Blog publishes detailed analysis of the Contagious Interview malware delivery campaign including BeaverTail, InvisibleFerret, and related tooling.","source":"Microsoft Security Blog","source_url":"https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/"},{"date":"2026-07-20","event":"SOCRadar Threat Research Unit publishes updated analysis of the ClickFake Interview campaign documenting PylangGhost and GolangGhost targeting Web3 professionals, with new infrastructure observations including Nuitka-compiled variants.","source":"SOCRadar","source_url":"https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/"},{"date":"2026-07-22","event":"GBHackers and Infosecurity Magazine publish coverage of the active ClickFake Interview campaign deploying PylangGhost and GolangGhost RATs.","source":"GBHackers / Infosecurity Magazine","source_url":"https://gbhackers.com/north-korean-hackers-use-fake-job-interviews/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision cc673d3b-0d24-4c2e-821a-2bd605e15d73
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.