Scan to download
BTC $66,012.75 -2.16%
ETH $1,942.72 -4.56%
BNB $613.41 -1.63%
XRP $1.42 -4.56%
SOL $81.67 -4.53%
TRX $0.2795 -0.47%
DOGE $0.0974 -3.83%
ADA $0.2735 -4.22%
BCH $467.50 -3.86%
LINK $8.64 -2.97%
HYPE $28.98 -1.81%
AAVE $122.61 -3.42%
SUI $0.9138 -6.63%
XLM $0.1605 -4.62%
ZEC $260.31 -8.86%
BTC $66,012.75 -2.16%
ETH $1,942.72 -4.56%
BNB $613.41 -1.63%
XRP $1.42 -4.56%
SOL $81.67 -4.53%
TRX $0.2795 -0.47%
DOGE $0.0974 -3.83%
ADA $0.2735 -4.22%
BCH $467.50 -3.86%
LINK $8.64 -2.97%
HYPE $28.98 -1.81%
AAVE $122.61 -3.42%
SUI $0.9138 -6.63%
XLM $0.1605 -4.62%
ZEC $260.31 -8.86%

North Korean hackers deploy new malware that supports credential theft from browser extensions

2025-06-20 14:35:24
Collection

ChainCatcher news, according to Decrypt, the threat intelligence research company Cisco Talos reported on Wednesday that North Korean hackers are targeting cryptocurrency professionals by deploying a new Python remote access Trojan named "PylangGhost" through fake interviews disguised as recruiters from companies like Coinbase and Uniswap. This malware is associated with the notorious North Korean hacking group "Famous Chollima" (also known as "Wagemole").

The malware can steal credentials from over 80 browser extensions, including Metamask and 1Password, and achieve persistent remote access. The attacks primarily target Windows systems and macOS users, while Linux systems have not been affected by the current wave of attacks.

app_icon
ChainCatcher Building the Web3 world with innovations.