币界网报道:North Korean hacking group Famous Chollima is targeting crypto professionals with a Python-based malware called PylangGhost, disguised as part of fake job applications from companies like Coinbase and Uniswap, according to Cisco Talos. The malware, a variant of the GolangGhost RAT, infects victims through staged "skill tests" that prompt them to install malicious code. Primarily affecting Windows users in India with blockchain experience, the RAT steals credentials, wallet data from MetaMask and other extensions, and enables full remote control via RC4-encrypted HTTP packets. The group, active since mid-2024, uses sophisticated fake career sites to lure software engineers and marketers.