Famous Chollima’s PylangGhost

2025-06-23 Poly Swarm

https://blog.polyswarm.io/famous-chollimas-pylangghost

Thumbnail for Famous Chollima’s PylangGhost

Famous Chollima, described as a North Korean-aligned actor, deployed the Python-based PylangGhost RAT against cryptocurrency and blockchain professionals, primarily in India. The campaign used fake recruiter personas and counterfeit job-application sites impersonating companies such as Coinbase and Robinhood to convince victims to run PowerShell Invoke-WebRequest or curl commands. The downloaded ZIP contained Python modules, a VBS script, and a renamed Python interpreter disguised as nvidia.py, which established registry persistence, generated a system GUID, and communicated with C2 over RC4-encrypted HTTP. PylangGhost mirrors GolangGhost functionality, enabling remote control, file operations, and credential theft from more than 80 browser extensions, including cryptocurrency wallets and password managers. The targeting and tooling point to financially motivated operations against crypto-sector users where stolen credentials and wallet access can directly support DPRK revenue generation.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c2137cd870de0af6662f56c97d27b86… 2025-06-18 2025-06-23

Related Actors

Related Reports

« Back