북한 Lazarus(라자루스) 에서 만든 신형 RAT PyLangGhost RAT 분석-auto.py(2025.8.7)

2025-08-18 Sakai Analysis of the New RAT PyLangGhost RAT Created by North Korean Lazarus - auto.py (2025.8.7)

https://wezard4u.tistory.com/429572

Thumbnail for 북한 Lazarus(라자루스) 에서 만든 신형 RAT PyLangGhost RAT 분석-auto.py(2025.8.7)

A Korean malware analysis attributes the auto.py sample to Lazarus/Famous Chollima and identifies it as part of the PyLangGhost RAT tooling. The script is described as collecting Chrome extension local storage from multiple browser profiles, which could expose wallet, OTP, and other extension data. It also checks for administrator rights, abuses LSASS token impersonation and Windows DPAPI/CNG paths, and derives Chrome v10/v20 master keys to decrypt stored browser passwords. The body lists hashes for the sample and explains how decrypted credentials are written to a log and returned, making the malware relevant to DPRK-linked credential and cryptocurrency theft tracking.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0da2437fb9c4e371618351f8fabc673… 2025-08-18 2025-08-18
HASH 29cfa008d4364c526f7c82ba1bef7cb0 2025-08-18 2025-08-18
HASH bb794019f8a63966e4a16063dc785fa… 2025-08-06 2025-08-18

Related Reports

« Back