북한 Lazarus(라자루스) 에서 만든 신형 RAT PyLangGhost RAT 분석-auto.py(2025.8.7)
2025-08-18 • Sakai • Analysis of the New RAT PyLangGhost RAT Created by North Korean Lazarus - auto.py (2025.8.7) •
A Korean malware analysis attributes the auto.py sample to Lazarus/Famous Chollima and identifies it as part of the PyLangGhost RAT tooling. The script is described as collecting Chrome extension local storage from multiple browser profiles, which could expose wallet, OTP, and other extension data. It also checks for administrator rights, abuses LSASS token impersonation and Windows DPAPI/CNG paths, and derives Chrome v10/v20 master keys to decrypt stored browser passwords. The body lists hashes for the sample and explains how decrypted credentials are written to a log and returned, making the malware relevant to DPRK-linked credential and cryptocurrency theft tracking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0da2437fb9c4e371618351f8fabc673… | 2025-08-18 | 2025-08-18 |
| HASH | 29cfa008d4364c526f7c82ba1bef7cb0 | 2025-08-18 | 2025-08-18 |
| HASH | bb794019f8a63966e4a16063dc785fa… | 2025-08-06 | 2025-08-18 |