Fake Web3 Job Interviews Push “ClickFix” Malware

Infosecurity Magazine · High sophistication
Last updated July 30, 2026

Researchers say a North Korea-aligned group is targeting Web3 and crypto professionals with fake recruiter outreach and “mandatory” online skill tests. During the test, victims are tricked into copying a terminal command to “fix” a camera/mic error, which installs remote-access malware and can lead to credential and crypto-wallet theft.

How the attack worked

The campaign begins with fake recruiter outreach on LinkedIn, Telegram, Discord, or direct email. Attackers pose as recruiters from reputable firms, or invent entirely fictitious web companies, and target developers and administrators with highly lucrative salary packages and prestigious career advancement. Once a candidate engages, they are told the next step is a mandatory skill assessment test and directed to an attacker-controlled online platform.

During the assessment, the portal displays a fake camera or microphone error. To resolve it and continue with the interview, the page instructs the candidate to copy and paste a diagnostic command into their system terminal. This is a ClickFix-style lure: the command actually downloads and installs malware. On Windows systems, this can lead to a PowerShell and curl chain that fetches a ZIP file and loads the PylangGhost RAT. On macOS, victims may receive GolangGhost along with a helper application that attempts to trick users into surrendering their administrative password.

Why it succeeded

The assessment portals are built to manufacture urgency and suppress verification. Countdown timers create psychological pressure, and automated warnings appear if the candidate tries to switch browser tabs, which discourages research into the suspicious behavior of the page. By capitalizing on a candidate's desire to perform well against the clock, the attackers bypass the instinct to pause and question an unusual request.

The pretext also exploits the norms of legitimate hiring processes. Skill assessments, coding tests, and platform-based interviews are common in tech recruiting, so a request to fix a technical error feels plausible rather than alarming.

What to watch for

  • A job interview or skill test that asks you to run a terminal or command-line instruction
  • Countdown timers or tab-switch warnings designed to discourage pausing or researching
  • Recruiter contact via LinkedIn, Telegram, Discord, or email offering unusually high compensation for a fast-tracked process
  • Any request, during an interview, to enter an administrative password or install additional software
  • End targets that include crypto wallet browser extensions such as MetaMask, Phantom, and TronLink, and password managers like NordPass

How to build resistance

Organizations should train developers, administrators, and anyone using crypto wallets or password managers to treat terminal-command requests during a hiring process as an automatic stop-and-verify moment. Awareness efforts should reinforce that legitimate assessments do not require running system commands or entering admin credentials, and that recruiter identities on professional networks should be verified independently before proceeding. Because personal job searches sometimes happen on company devices, reminding staff not to mix work and personal job-hunting activity can reduce the chance that a personal scam becomes an organizational incident.

Mapping this activity to techniques such as spearphishing via service (T1566.003), user execution (T1204.002), and command and scripting interpreter use (T1059) can help defenders build detection and training scenarios around the same behaviors observed here.

Key findings

  • Attackers pose as recruiters (real or fictitious companies) and offer “highly lucrative salary packages” to lure Web3 candidates into a “mandatory skill assessment test.”
  • Victims are sent to attacker-controlled interview/assessment portals with countdown timers, tailored questions, and tab-switch warnings to pressure compliance and discourage research.
  • The portal triggers a fake camera/microphone error and instructs the victim to copy/paste a terminal “diagnostic command,” a ClickFix-style lure that leads to malware installation.
  • Windows victims may receive a chain that uses PowerShell/curl to fetch a ZIP and ultimately loads the PylangGhost RAT; macOS victims may fetch GolangGhost and a helper app that steals admin passwords.
  • The end goal is asset theft: the stealer targets crypto wallet browser extensions (e.g., MetaMask, Phantom, TronLink) and password managers (e.g., NordPass).

Who’s being targeted

  • Commonly targeted roles: Engineering (Web3/crypto developers), IT administrators, Anyone using crypto wallets or password managers, HR/Recruiting (for awareness of recruiter-impersonation risk).
  • Affected industries: Cryptocurrency/Web3, Financial services (digital assets), Information technology (developers/admins).
  • Attack channels: linkedin, website, telegram, email.
  • Impersonated: Recruiter from a reputable firm (or a fictitious web company), Recruiter / hiring team, Recruiter / assessment platform support.

Red flags to watch for

  • Unusually high salary/fast-tracked prestige used to rush compliance
  • Assessment page creates pressure with countdown timers and tab-switch warnings
  • Website asks you to run terminal commands to fix an interview “error”
  • Gated portal discourages verification (e.g., warns on tab-switch)
  • High interactivity designed to build trust rather than normal hiring process
  • Running shell/terminal commands for an interview is abnormal
  • A hiring test should not require installing software or entering an admin password
  • Terminal commands delivered by a website/email are high risk
  • Pressure tactics (“against the clock”) to reduce careful review
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake Web3 job interview attack work?

Attackers pose as recruiters on LinkedIn, Telegram, Discord, or email and offer high-paying Web3 roles that require a mandatory skill assessment. The assessment portal fakes a camera or microphone error and instructs the candidate to copy and paste a diagnostic command into their terminal, which actually installs malware.

What happens after the malicious command is run?

On Windows, the command chain uses PowerShell and curl to fetch a ZIP file that loads the PylangGhost RAT. On macOS, victims may fetch GolangGhost along with a helper app designed to steal admin passwords.

What data are the attackers after?

The malware targets crypto wallet browser extensions like MetaMask, Phantom, and TronLink, as well as password managers such as NordPass, with the end goal of stealing credentials and digital assets.

What are the warning signs of this scam?

Red flags include unusually high salary offers, countdown timers and tab-switch warnings on the assessment portal, and any request to run terminal commands or enter an admin password as part of a job interview.

Read the video transcript

You get a LinkedIn message: Web3 role, huge salary, and a mandatory online skill test. Sounds amazing, right? You click through to their “assessment portal.” There’s a countdown timer, warnings if you switch tabs, and then, fake camera error. It tells you: copy this terminal command to fix your mic and continue the interview. That one paste can quietly drop remote-access malware like PylangGhost or GolangGhost, then go after your MetaMask, Phantom, TronLink, even your password manager. A fake interview turns into drained wallets and stolen creds. Here’s the rule: if any interview or “skill test” asks you to run a terminal or PowerShell command, stop immediately and verify the recruiter and site through a separate, trusted channel.

Similar attacks

Steam Game Lure Led to $220K Crypto Theft

Steam Game Lure Led to $220K Crypto Theft

Federal investigators arrested a Florida man accused of helping push malware disguised as video games, which infected about 8,000 devices and enabled theft…

July 20, 2026
Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

July 17, 2026