North Korean Hackers Target LinkedIn Users With Fake Job Offers

KnowBe4 Team | Aug 19, 2026

Hackers with the North Korean threat actor Famous Chollima are posing as recruiters on LinkedIn and attempting to trick users into falling for ClickFix attacks, according to researchers at SOCRadar.

“In the latest variant of the ClickFake campaign, Famous Chollima actors rely on social engineering, posing as potential recruiters to convince targets into a skill assessment, part of a fake interview, and run malicious payloads,” SOCRadar says. “They occasionally create fake front companies or impersonate known ones in the crypto and Web3 industries, and reach out to their targets via social media (LinkedIn, Discord, Telegram and Email).”

At the end of the phony interview process, the attackers fabricate a problem that the user supposedly needs to fix. This is when the ClickFix attack is launched: the attackers send the victim instructions to paste a command into their computer, which will result in malware installation.

“After convincing them with the pretext of high salaries, they send out an invitation for a skill assessment on their infrastructure. Their targets include non-technical profiles such as advisors, investment partners, and business intelligence analysts. The fake assessment includes multiple choice questions as part of the tasks of each role, as well as a final question in the end to record themselves answering it. The final lure is that something is not working with the camera or the microphone on this last step, and ClickFix instructions are presented to the target to resolve the issue.”

DPRK threat actors have been using job-themed attack campaigns for years, often landing remote jobs at U.S. organizations by posing as legitimate IT workers. KnowBe4 itself was among the first to spread wide awareness about this issue when we were targeted by a fake North Korean IT worker in 2024. The individual was detected before they could exfiltrate any data, but the incident demonstrated the effectiveness of AI-enhanced social engineering.

SOCRadar has the story: Who Needs a Job? DPRK ClickFake Interview Campaign Drops PylangGhost and GolangGhost RATs

 

FAQs

What is a ClickFix attack?

ClickFix is a social engineering technique where attackers fabricate a technical problem — a broken camera, microphone, or page error — and present "fix" instructions that tell the victim to paste a command into their own computer. Running that command installs malware. Because the victim executes it manually, the attack sidesteps many automated defenses.

Who is Famous Chollima?

Famous Chollima is a North Korean state-aligned threat actor known for job- and recruitment-themed attack campaigns. According to SOCRadar, the group poses as recruiters on LinkedIn, Discord, Telegram, and email, sometimes operating fake front companies in the crypto and Web3 sectors to add credibility.

How can organizations defend against fake recruiter and ClickFix attacks?

Train employees on the single rule that legitimate support or assessment processes never ask you to paste a command into a terminal, Run dialog, or PowerShell window. Pair that with verification habits for unsolicited recruiter contact, restrictions on script execution where feasible, and a clear internal reporting path so a near-miss gets escalated rather than ignored.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.