Fake Job Interview Lure Targets Crypto Staff

Graham Cluley · High sophistication
Last updated July 30, 2026

A North Korea-linked group is running fake recruitment campaigns to trick people into taking “online assessments” for jobs that don’t exist. The goal is to harvest personal details and potentially compromise corporate access, especially targeting non-technical staff in crypto firms who can influence or authorize financial activity.

How the attack worked

This campaign, attributed to a North Korea-linked group known as Famous Chollima or Wage Mole, begins with outreach on LinkedIn. Attackers pose as recruiters for a cryptocurrency company, either inventing an entirely fake business or impersonating a real one using convincing websites and typosquatted domains. Targets are told they are a strong fit for a high-paying role and are directed to complete a short online assessment as the next step.

The assessment itself is designed to look professional and legitimate. It asks applicants to fill in extensive personal and career details, including name, email, LinkedIn URL, phone number, and work history. In some versions, applicants are asked to turn on their webcam, framed as a way to ensure they are not cheating on a basic multiple-choice test. Every detail submitted is handed directly to the attackers.

Why it succeeded

The campaign works because it mirrors a normal, low-friction hiring experience. A recruiter reaching out unprompted, a slick assessment portal, and a request for standard application information all look ordinary on the surface. By impersonating real crypto firms or building believable fake ones, attackers reduce the skepticism a target might otherwise apply to an unsolicited job offer.

The targeting strategy also matters. Rather than focusing on developers or technical staff, the group prioritizes non-technical roles in finance, legal, compliance, and executive support, people who may have access to company funds or know people who do. This shifts the payoff from a technical compromise to a faster path toward financial access or influence.

What to watch for

  • An unsolicited recruiter message that quickly moves to a link for an

Key findings

  • Researchers describe a “ClickFake interview attack” tied to a North Korean group (Famous Chollima / Wage Mole).
  • Attackers create fake companies or impersonate real crypto firms using convincing websites and typosquatted domains.
  • Targets are recruited via LinkedIn and pushed to complete a slick-looking online assessment that collects extensive personal and career details.
  • The campaign reportedly focuses on non-technical roles (legal, compliance, finance) that may have access to funds or influence people who do.

Who’s being targeted

  • Commonly targeted roles: Finance, Legal, Compliance, HR/Recruiting, Executive assistants, All employees active on LinkedIn.
  • Affected industries: Cryptocurrency, Fintech, Financial services.
  • Attack channels: linkedin, website.
  • Impersonated: Recruiter for a cryptocurrency company (real or fake brand), Hiring team / online assessment portal for the crypto employer.

Red flags to watch for

  • Job opportunity comes via unsolicited recruiter message and quickly pushes a link to an “assessment”
  • Request to provide extensive personal details early (email, phone, LinkedIn URL, work experience)
  • Pressure to turn on webcam as part of a basic multiple-choice “test”
  • Assessment portal collects more information than needed for an initial screening
  • Brand-new or unfamiliar company with limited verifiable history
  • Assessment feels like a data-harvesting funnel rather than a genuine interview step
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the ClickFake interview attack?

It is a campaign tied to a North Korean-linked group (Famous Chollima, also known as Wage Mole) that creates fake companies or impersonates real crypto firms to lure job seekers into completing a fake online assessment that harvests personal and career details.

Who is being targeted by this fake job scam?

The campaign focuses on non-technical staff such as finance, legal, compliance, and HR/recruiting employees who may have access to company funds or influence over people who do, rather than developers.

What are the warning signs of this attack?

Red flags include unsolicited recruiter messages that quickly push an assessment link, requests for extensive personal details early on, and pressure to enable a webcam during a basic multiple-choice test.

Why do attackers ask for a webcam during the assessment?

According to the source, attackers frame the webcam request as a way to prove the applicant is not cheating on the assessment, which is really a pretext to gather more information or verify identity for their scam.

Read the video transcript

Imagine this: LinkedIn ping, ‘We’ve decided you’re the person for this role. Just complete a short online assessment.’ That’s the “ClickFake interview” attack, linked to the Famous Chollima group. They spin up fake or typosquatted crypto companies and funnel you to a slick assessment site. You’re asked for name, email, LinkedIn URL, phone, work history, and even to turn on your webcam for a basic multiple-choice test. All of that flows straight to them, especially targeting finance, legal, and compliance staff. If a recruiter you don’t know pushes an instant assessment link, stop. Look up the company and recruiter yourself in a new tab, only use links you find, not the ones they send.

Similar attacks