Fake Camera Troubleshooting Commands Deliver RATs Across Windows and macOS

A North Korean-aligned threat actor is using fake job interviews and bogus camera troubleshooting prompts to infect Windows and macOS users with remote access trojans (RATs).

The campaign, tracked as ClickFake Interview, targets cryptocurrency and Web3 professionals, including non-technical staff who may have access to corporate systems, investor information, or digital assets.

Threat researchers attribute the activity to Famous Chollima, also known as Wagemole.

The group poses as recruiters from fabricated firms or impersonates legitimate crypto and HR brands. Contacts targets through LinkedIn, Discord, Telegram, email, and other social platforms.

Victims are invited to complete a professional-looking online skill assessment for roles such as legal advisor, investment partner, financial manager, compliance officer, business intelligence analyst, or product leader.

The sites use role-specific questions, countdown timers, tab-switch warnings, and video-recording requests to make the interview appear legitimate and pressure candidates into following instructions.

Fake Camera Fixes Deploy RATs

At the final video-recording stage, the malicious site displays a fake camera or microphone error. It offers a “how to fix” option.

This is a ClickFix-style lure, victims are instructed to copy and paste a command into Windows Run, Command Prompt, PowerShell, or macOS Terminal.

ClickFake Interview attack chain (Source: socradar)
ClickFake Interview attack chain (Source: socradar)

The visible command appears harmless, often masquerading as a graphics-driver update from Microsoft or a macOS software package.

However, the website hijacks the browser clipboard when the victim copies the displayed text. The pasted content includes the decoy command but silently appends commands that download and execute malware.

On Windows, the malicious command retrieves a ZIP archive, expands it through PowerShell, and launches a Visual Basic Script file with wscript.

The script deploys a bundled Python environment and loads PylangGhost, a RAT compiled as Python dynamic modules using Nuitka.

PylangGhost establishes Registry Run-key persistence, profiles the victim device, receives remote shell commands, uploads or downloads files, and communicates with command-and-control infrastructure over HTTP.

The malware can also target Chromium browser credentials, cookies, password data, cryptocurrency wallet extensions, and password manager extensions.

ClickFix panel functionality flow (Source: socradar)
ClickFix panel functionality flow (Source: socradar)

The RAT specifically searches for extensions associated with wallets such as MetaMask, Coinbase Wallet, Trust Wallet, Binance Wallet, Rabby Wallet, Phantom alternatives, and other Web3 tools.

It can also attempt to bypass Chrome’s App-Bound Encryption protections to recover stored credentials

macOS victims receive a different chain. The copied command downloads and runs a Bash script that creates a hidden working directory, downloads a Go runtime, and launches GolangGhost, the macOS variant of the RAT, socradar said.

Indicators of Compromise

IOC TypeIndicatorContext
C2 IP address95.216.92.207:8080PylangGhost command-and-control server
Malicious domainapp.breezyhr.usFake assessment backend and payload delivery

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories