
Steam Game Lure Led to $220K Crypto Theft
Federal investigators arrested a Florida man accused of helping push malware disguised as video games, which infected about 8,000 devices and enabled theft…
Researchers say a North Korea-aligned group is targeting Web3 and crypto professionals with fake recruiter outreach and “mandatory” online skill tests. During the test, victims are tricked into copying a terminal command to “fix” a camera/mic error, which installs remote-access malware and can lead to credential and crypto-wallet theft.
The campaign begins with fake recruiter outreach on LinkedIn, Telegram, Discord, or direct email. Attackers pose as recruiters from reputable firms, or invent entirely fictitious web companies, and target developers and administrators with highly lucrative salary packages and prestigious career advancement. Once a candidate engages, they are told the next step is a mandatory skill assessment test and directed to an attacker-controlled online platform.
During the assessment, the portal displays a fake camera or microphone error. To resolve it and continue with the interview, the page instructs the candidate to copy and paste a diagnostic command into their system terminal. This is a ClickFix-style lure: the command actually downloads and installs malware. On Windows systems, this can lead to a PowerShell and curl chain that fetches a ZIP file and loads the PylangGhost RAT. On macOS, victims may receive GolangGhost along with a helper application that attempts to trick users into surrendering their administrative password.
The assessment portals are built to manufacture urgency and suppress verification. Countdown timers create psychological pressure, and automated warnings appear if the candidate tries to switch browser tabs, which discourages research into the suspicious behavior of the page. By capitalizing on a candidate's desire to perform well against the clock, the attackers bypass the instinct to pause and question an unusual request.
The pretext also exploits the norms of legitimate hiring processes. Skill assessments, coding tests, and platform-based interviews are common in tech recruiting, so a request to fix a technical error feels plausible rather than alarming.
Organizations should train developers, administrators, and anyone using crypto wallets or password managers to treat terminal-command requests during a hiring process as an automatic stop-and-verify moment. Awareness efforts should reinforce that legitimate assessments do not require running system commands or entering admin credentials, and that recruiter identities on professional networks should be verified independently before proceeding. Because personal job searches sometimes happen on company devices, reminding staff not to mix work and personal job-hunting activity can reduce the chance that a personal scam becomes an organizational incident.
Mapping this activity to techniques such as spearphishing via service (T1566.003), user execution (T1204.002), and command and scripting interpreter use (T1059) can help defenders build detection and training scenarios around the same behaviors observed here.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers pose as recruiters on LinkedIn, Telegram, Discord, or email and offer high-paying Web3 roles that require a mandatory skill assessment. The assessment portal fakes a camera or microphone error and instructs the candidate to copy and paste a diagnostic command into their terminal, which actually installs malware.
On Windows, the command chain uses PowerShell and curl to fetch a ZIP file that loads the PylangGhost RAT. On macOS, victims may fetch GolangGhost along with a helper app designed to steal admin passwords.
The malware targets crypto wallet browser extensions like MetaMask, Phantom, and TronLink, as well as password managers such as NordPass, with the end goal of stealing credentials and digital assets.
Red flags include unusually high salary offers, countdown timers and tab-switch warnings on the assessment portal, and any request to run terminal commands or enter an admin password as part of a job interview.
You get a LinkedIn message: Web3 role, huge salary, and a mandatory online skill test. Sounds amazing, right? You click through to their “assessment portal.” There’s a countdown timer, warnings if you switch tabs, and then, fake camera error. It tells you: copy this terminal command to fix your mic and continue the interview. That one paste can quietly drop remote-access malware like PylangGhost or GolangGhost, then go after your MetaMask, Phantom, TronLink, even your password manager. A fake interview turns into drained wallets and stolen creds. Here’s the rule: if any interview or “skill test” asks you to run a terminal or PowerShell command, stop immediately and verify the recruiter and site through a separate, trusted channel.

Federal investigators arrested a Florida man accused of helping push malware disguised as video games, which infected about 8,000 devices and enabled theft…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…