GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

A new malware campaign is targeting cryptocurrency and Web3 professionals through fake job interviews.

The operation delivers GolangGhost, a remote access trojan that can steal browser credentials, collect wallet data, and give attackers control of infected macOS systems.

The attackers pose as recruiters, offer attractive roles, and direct targets to fake online skill assessments.

At the final video-recording stage, the site displays a false camera error and persuades victims to copy and paste a supposed fix into their Mac Terminal.

SOCRadar said in a report shared with Cyber Security News (CSN) that the campaign is linked to the North Korean-aligned Famous Chollima group, also tracked as Wagemole.

The campaign delivers PylangGhost to Windows users and GolangGhost to macOS users through the same deceptive recruitment process.

Financially motivated DPRK campaigns (Source - SOCRadar)
Financially motivated DPRK campaigns (Source – SOCRadar)

The risk extends beyond a single compromised device. People working in crypto, investment, legal, advisory, and business roles may hold direct access to wallets, company accounts, or sensitive information that attackers can use to steal digital assets or move deeper into an organization.

Similar fake recruiter malware campaigns have repeatedly targeted the crypto sector.

GolangGhost Steals Chrome Secrets

On macOS, the copied command starts a Bash script that creates a hidden working directory, downloads a fake Intel driver archive, and retrieves the Go compiler needed to run GolangGhost.

The script also establishes persistence through a Launch Agent, allowing the malware to restart after a reboot.

GolangGhost can use the macOS Keychain command-line utility to retrieve Chrome’s stored master password. It then applies that secret to decrypt Chrome’s local database, exposing saved browser credentials and cookies that may grant access to online services.

ClickFake Interview attack chain (Source - SOCRadar)
ClickFake Interview attack chain (Source – SOCRadar)

This mirrors the danger seen in macOS credential stealing malware, which has also targeted browser data and wallet information.

The malware also searches for browser extension data associated with cryptocurrency wallets and password managers.

Its targets include MetaMask and several other wallet extensions, enabling attackers to collect extension settings and related data from Chrome profiles.

More concerningly, GolangGhost can alter Chrome’s Secure Preferences file after forcing the browser to close.

The malware injects broad permissions, including access to active tabs, clipboard writing, web requests, and expanded storage, then assigns them to the MetaMask extension. That change could let attackers abuse the wallet extension’s trusted browser position.

Fake Interviews Drive Infection

The ClickFake interview pages are designed to make victims act quickly. They collect personal information, fingerprint the visitor’s browser and device, block mobile users, show timed assessment questions, and display warnings when candidates switch browser tabs.

At the final step, the attackers present a realistic camera or microphone troubleshooting prompt.

The page replaces the harmless command copied by the victim with a malicious one, while displaying the expected text in Terminal to reduce suspicion.

Recent ClickFix malware campaigns show how this approach turns a victim’s own action into initial access.

Sample ClickFix instruction from the ClickFake Campaign (Source - SOCRadar)
Sample ClickFix instruction from the ClickFake Campaign (Source – SOCRadar)

The campaign also launches a fake macOS application that requests administrator credentials under the guise of an update.

Those credentials are sent to attacker-controlled infrastructure, adding another path to account takeover and device control.

Organizations should train staff, especially non-technical employees, to treat unsolicited interview requests and copy-and-paste troubleshooting steps as warning signs.

Security teams should prevent personal job hunting on corporate devices, review unexpected Launch Agents and browser-preference changes, and use detections that inspect suspicious compiled modules and dynamic libraries.

The threat also reinforces why teams should avoid untrusted recruitment software packages during hiring conversations.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain paxos-apply.com Fake recruitment infrastructure
Domain cameradriverupdates.com Fake recruitment infrastructure
Domain highmatch.pro Fake recruitment infrastructure
Domain highmatch.cloud Fake recruitment infrastructure
Domain tailora.org Fake recruitment infrastructure
Domain breezyhr.us Typosquatted recruitment platform
Domain rolevia.us Fake recruitment infrastructure
Domain medincahub.com Fake recruitment infrastructure
Domain cincopa.org Fake recruitment infrastructure
Domain knockri.us Fake recruitment infrastructure
Domain spiralboard.com Fake recruitment infrastructure
Domain kaltura.studio Fake recruitment infrastructure
Domain paxos-video-interviews.com Fake recruitment infrastructure
Domain videohirepro.com Fake recruitment infrastructure
Domain evaluateproficiency.com Fake recruitment infrastructure
Domain paxos-video-recording.com Fake recruitment infrastructure
Domain video-hiring.com Fake recruitment infrastructure
Domain vervoe.app Fake recruitment infrastructure
Domain canditech.us Fake recruitment infrastructure
Domain hirvexo.com Fake recruitment infrastructure
Domain hiring-you.com Fake recruitment infrastructure
Domain gumlet.us Fake recruitment infrastructure
Domain survicate.us Fake recruitment infrastructure
Domain ziggeo.tech Campaign infrastructure
Domain insighboard.com Campaign infrastructure
Domain zavnia.us Campaign infrastructure
Domain mettl.us Campaign infrastructure
Domain tecmlny.com Campaign infrastructure
Domain zynoracreative.com Campaign infrastructure
Domain workbright.us Campaign infrastructure
Domain me-c0h.pages.dev Campaign infrastructure
Domain evaluza.com Campaign infrastructure
Domain evaluino.com Campaign infrastructure
Domain nvidiadriver.net Payload hosting domain
IP Address 95.216.92.207 Command-and-control infrastructure
URL hxxp://nvidiadriver.net/verv1432/drivers/intel-driver-xd7d.zip GolangGhost payload archive
URL hxxp://95.216.92.207:8080 Command-and-control endpoint
URL hxxp://95.216.92.207:8080/gettext Credential exfiltration endpoint
SHA-256 96ce1b7f2026dfd3dbb806c246c27ce3b105a9e78482956fae42258980425cd0 ClickFix-related file
SHA-256 b9a8ae1e6d2c875e21c77f3b9255ca0b3b0b3e0addbb2c3c865e5b95eb734d22 winPatch-related file
SHA-256 466170079e4b9e26e41a25ca45ff8a7f6cc9b3e9e7f2beda99f3dd042e72c1b update.vbs
SHA-256 164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3 audiodriver module
SHA-256 df6669bd504ce6b0e303be7ee47f2ebbc062989c88c41f0a3f436044a24869798 config module
SHA-256 50ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdf api module
SHA-256 3c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2 command module
SHA-256 282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990 util module
SHA-256 17832aa629524ef6e8d8d6e9b6b902a8d324b559e3c36dbd0e221ab1690be871 auto module
SHA-256 0ca62fe52a895bad73a14f1a455e1bead18b8c256749d727c2678924298f7ee8 macPatch.sh
SHA-256 617779f417c1850c08ed55ba49e2317aed0e1e911fca8bf8f348189ee4ebdb97 drivfixer.sh
SHA-256 ee59683f2ab7ba05da5443a153aee221af08ba884461f74dd8b114c0d10febbeb main.go
SHA-256 337dfb06e08ac8ceb47728b50de006ef82f5e61fa245494210a362bab15859f coreiter.go
SHA-256 f53567c1a8885925393a1771cded2ff2c8ef4ab38da1bf97d36f153f81f72e80 instancecheck.go
SHA-256 95983760b571631e1da0f52f51c7a274f2a34e44de5e3d10cadcf8b30edf959c commandstackcmd.go
SHA-256 6110ea43d734a296a8e5676192c56cdbdad11c94c3eecda7b55a4672e16d35d4 configconstants.go
SHA-256 6295839b6c9414d9cd0f2402f4cd72e219f75cc4dfac720cec297fddc4f20ff2 utilcompress.go
SHA-256 6850cdb307fc72e052719939efbf705beb8d50775b260a18aff0adba536d7dea transporthtxp.go
SHA-256 4387b79045065622e7fd643b65d85998f092c4b32e53633d36bd7ef46181cbe2 autobasic.go
SHA-256 0827606854b6fd7fa73f13f2e453d9720d79c63e89308cfed0b577a16d84bccd autchromechangepref.go
SHA-256 756846dfa3c258807b6962bb66373a543aa6b4ba0a35ffc4a526e4b07a84d9dc autochromecookiedarwin.go
SHA-256 319adf187bce5bd85dbb5b06f99ce78baa807af590feaed44a6f932d4d5b9003 autochromecookieother.go
SHA-256 d1934fdd449b6e8124b632f680cbe6893ac39e740559b1882641204040c70a99 autochromecookiewin.go
SHA-256 47a3ce02388c845e5f1ed8f4d3673e2c99a643b88d3f2fa06cbfe0c78502264d autochromegather.go
SHA-256 1cee591c63d7fd8ee963abb29789c3ee41eb42cc77470964a00ea15be4b51341 CodeFixerNow.app
SHA-256 9e465904503815c27397e082fd5ca8eb30d99d8d256c6a0949696d1830c8bb53 CodeFixerNow.debug.dylib

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposuremalware to businesses an

The post GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions appeared first on Cyber Security News.