Innovation Insurance Group

  • About
    • Company Profile
      • Annual Reports
        • 2014 Annual Report
        • 2013 Annual Report
    • Ty R. Sagalow
  • Our Services
    • Expert Witness
    • InsurTech
    • Product Development
      • Product Development Case Studies
    • Directors and Officers Insurance
    • Cyber Risk Insurance
    • Bitcoin Insurance Agency
      • BitCoin 101
      • Bitcoins FAQ
      • Bitcoin Video Series
      • Publications and Interviews
  • News
    • Speaking Engagements
    • IIG in the News
    • Bitcoin Industry News
    • Events
    • World Risk and Insurance News
      • Web Series Hosted
        by Ty Sagalow
        • What’s New in Insurance?
        • Innovations in Insurance
      • Interviews of
        Ty Sagalow
    • Gallery
  • Leadership
    • Publications and Interviews
      • Innovation and Product Development
      • D&O Insurance
      • Cyber Risk Insurance
      • Reputation Risk
      • Bitcoin
    • Innovation
    • Emerging Risks
      • InsurTech
      • Reputation Risk
      • Crowdfunding
      • Bitcoin Risk
      • Cyber Risk
    • Thoughts from Industry Leaders
  • Clients
    • Clients
    • Partners
      • Advisen, Ltd.
      • Hanover Stone Partners, LLC
      • CLM Advisors
  • Lemonade Book
    • Book Store – Buy the Book
    • Book Overiew
    • Interviews with the Author
    • Book Signing Gallagy
  • Contact Us
You are here: Home / Bitcoin Industry News / North Korean Hackers Are Targeting Top Crypto Firms With Malware Hidden in Job Applications

June 20, 2025

North Korean Hackers Are Targeting Top Crypto Firms With Malware Hidden in Job Applications

A North Korean hacking group is targeting crypto workers with a Python-based malware disguised as part of a fake job application process, researchers at Cisco Talos said earlier this week.

Most victims appear to be based in India, according to open-source signals, and seem to be individuals with prior experience in blockchain and cryptocurrency startups.

While Cisco reports no evidence of internal compromise, the broader risk remains clear: That these efforts are trying to gain access to the companies these individuals might eventually join.

The malware, called PylangGhost, is a new variant of the previously documented GolangGhost remote access trojan (RAT), and shares most of the same features — just rewritten in Python to better target Windows systems.

Mac users continue to be affected by the Golang version, while Linux systems appear to be unaffected. The threat actor behind the campaign, known as Famous Chollima, has been active since mid-2024 and is believed to be a DPRK-aligned group.

Their latest attack vector is simple: impersonate top crypto firms like Coinbase, Robinhood, and Uniswap through highly polished fake career sites, and lure software engineers, marketers, and designers into completing staged “skill tests.”

Once a target fills in basic information and answers technical questions, they’re prompted to install fake video drivers by pasting a command into their terminal, which quietly downloads and launches the Python-based RAT.

(Cisco Telos)

The payload is hidden in a ZIP file that includes the renamed Python interpreter (nvidia.py), a Visual Basic script to unpack the archive, and six core modules responsible for persistence, system fingerprinting, file transfer, remote shell access, and browser data theft.

The RAT pulls login credentials, session cookies, and wallet data from over 80 extensions, including MetaMask, Phantom, TronLink, and 1Password.

The command set allows full remote control of infected machines, including file uploads, downloads, system recon, and launching a shell — all routed through RC4-encrypted HTTP packets.

RC4-encrypted HTTP packets are data sent over the internet that are scrambled using an outdated encryption method called RC4. Even though the connection itself isn’t secure (HTTP), the data inside is encrypted, but not very well, since RC4 is outdated and easily broken by today’s standards.

Despite being a rewrite, the structure and naming conventions of PylangGhost mirror those of GolangGhost almost exactly, suggesting both were likely authored by the same operator, Cisco said.

Read more: North Korean Hackers Targeting Crypto Developers With U.S. Shell Firms

Author: Shaurya Malwa

Filed Under: Bitcoin Industry News

Expert Witness

Ty Sagalow head shotTy Sagalow's unique background in legal, underwriting, policy drafting and claims – and his designation as a “qualified insurance expert” by the United States District Court for the Southern District of California – offers attorneys an unparalleled resource in D&O, E&O and Cyber insurance coverage disputes. He was also named "Most Helpful Expert" in a recent $8.7M coverage decision.

Mr. Sagalow served as Chief Underwriting Officer and General Counsel for AIG Executive Liability (formerly National Union Fire Insurance Company of Pittsburgh, PA), the world’s largest carrier of Directors and Officers Liability and Professional Liability Insurance. As General Counsel, Mr. Sagalow personally wrote or led teams that wrote all the D&O policies and many of the professional liability policies that AIG produced between 1988 and 2000 – policies which continue to serve as the foundational wording for the D&O and professional liability policies in the market today. As AIG Executive Liability’s Chief Underwriting Officer, Mr. Sagalow was charged with all underwriting interpretations and decisions for AIG D&O/E&O policies. In 2009, Mr. Sagalow headed up the team that rewrote all D&O policies for Zurich North America.

Ty is a cum laude graduate of Georgetown University Law Center and holds a LLM from New York University School of Law.

Bitcoin Insurance

Combining his talents as a network security insurance expert and an insurance product development expert, Ty Sagalow is the leading expert on the unique risk and insurance needs of the bitcoin industry.

With the successful sale of BitSecure(tm), the first bitcoin theft insurance policy in February of 2015, he is the first to create a sustainable, robust insurance policy to cover the theft of bitcoins and other virtual currency backed by an A-Rated, global “top 10” Property and Casualty insurance company.

Company Profile

Innovation Insurance Group is an insurance consulting firm and insurance brokerage founded by 30-year insurance executive, Ty R. Sagalow, former Chief Underwriting Officer, General Counsel and Chief Innovation Officer at AIG, and former Chief Innovation Officer at Zurich, NA and Tower Group. IIG focuses on three core practice groups: product development, expert witness services (primarily in the Management and Professional Liability areas), and bitcoin industry brokerage services.

Learn more about Ty R. Sagalow
Learn more about Innovation Insurance Group
Learn more about InsurTech Consulting
Learn more about Bitcoin Insurance Agency

Innovation Insurance Group, LLC BBB Business Review

Featured Topics

  • InsurTech
  • Innovation and Product Development
  • Directors & Officers Liability Insurance
  • Cyber Risk Insurance
  • Reputation Risk
  • Bitcoin Risk and Insurance
  • Emerging Risks
  • Interviews of Ty Sagalow
  • Gallery
  • Testimonials
  • Speaking Engagements

Featured Video Series

  • "What’s New in Insurance with Ty Sagalow"
  • "Innovations in Insurance hosted by
    Ty Sagalow"

Recent Speaking Events

  • Lawline How Is InsurTech Impacting the Insurance Industry? (Update) (8/16/23) (video)
  • The Future of Insurance (with Bryan Falchukc) (Video Podcast Aug 2022)
  • InsurTech Ohio Spotlight with Ty Sagalow (Podcast 5/10/22)
  • Meet the Godfather of Insurtech… (The Insurtech Leadership Podcast)(12/20/21)
  • Why Insurance Industry needs Lemonade Insurance-Style Business Models (Silicon Review, 2019)
  • CIIA Conference: Innovation, Culture and Technology
    May 13, 2021, Chili (Virtual)
  • Latin American Conference New Perspectives and Innovations for the Future of Insurance
    Nov 4, 2019, Mendoza, Argentina
  • All Speaking Engagements
  • 2016 Insurance Consultants Award
    2016 Insurance Consultants Award
  • 2017 Insurance Consultants Award
    2017 Insurance Consultants Award
  • 2017 Insurance Expert Witness of the Year
    2017 Insurance Expert Witness of the Year
  • AI 2017 InsurTech Consultant of the Year Award
    2017 InsurTech Consultant of the Year Award - AI International
  • 2018 Best Advisor Award – M&A Today
    2018 Best Advisor of the Year - M&A Today
  • 2018 Best Consulting Firm – Lawyers International
    2018 Best Consulting Firm - Lawyers International
  • 2018 Best Advisor of the Year - Corporate USA Today
    2018 Best Advisor of the Year - Corporate USA Today
  • 2018 Insuretech Consultant of the Year - Business Excellence
    2018 Insuretech Consultant of the Year - Business Excellence
  • 2019 50th Fasting Growing Company
    2019 50th Fasting Growing Company

Copyright © 2026 Innovation Insurance Group · Offices at Short Hills · 51 John F. Kennedy Parkway, First Floor West · Short Hills, NJ 07078 | Site Map | Log in