GolangGhost - Comprehensive Threat Intelligence Report

2025-08-25 Bloo

https://bloo.io/research/malware/golangghost

Thumbnail for GolangGhost - Comprehensive Threat Intelligence Report

GolangGhost is presented as a cross-platform remote access trojan associated with North Korea's Lazarus-linked Famous Chollima activity against cryptocurrency and blockchain job seekers. The infection chain uses fake recruitment sites and bogus video interview setups, where a ClickFix-style error prompt convinces victims to run commands in Windows CMD or macOS Terminal that install the backdoor. The malware and its Python variant PylangGhost can upload and download files, execute OS commands, collect system information, and steal browser data including passwords, cookies, and cryptocurrency wallet information. The excerpt lists multiple C2 domains and U.S.-hosted infrastructure, with targeting concentrated on cryptocurrency professionals and a small number of identified victims, notably in India.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 212.81.47.217 2025-06-18 2026-01-21
IPv4 31.57.243.29 2025-06-18 2026-01-21
IPv4 154.58.204.15 2025-06-18 2026-01-21
IPv4 31.57.243.190 2025-06-18 2026-01-21
IPv4 154.62.226.22 2025-03-31 2026-01-21
IPv4 38.134.148.218 2025-03-31 2026-01-21
HASH ba81429101a558418c80857781099e2… 2025-03-31 2025-08-25
HASH e88700d069a856e1a16c0da317a6f18… 2025-03-31 2025-08-25
HASH 0cbbf7b2b15b561d47e927c37f6e933… 2025-03-31 2025-08-25
HASH 6e186ada6371f5b970b25c78f38511a… 2025-03-31 2025-08-25
HASH d00ca82a32b5e8063492f27dfec225b… 2025-03-31 2025-08-25
HASH 887189269c3594e1a851eb22f7c174a… 2025-03-31 2025-08-25
HASH 6289ef57b1772d78da0e54ba4730b6f… 2025-03-31 2025-08-25
HASH b7b9e7637a42b5db746f1876a2ecb19… 2025-03-31 2025-08-25
HASH 3fec701b5e8486081c7062590f4ff94… 2025-03-31 2025-08-25
HASH ef9f49f14149bed09ca9f590d33e07f… 2025-03-31 2025-08-25
HASH f4b4411e403dd5094eef9c8946522fc… 2025-03-31 2025-08-25
DOMAIN api.camdriversupport.com 2025-03-31 2025-08-25
DOMAIN talenthiring360.com 2025-03-31 2025-08-25
DOMAIN vid-crypto-assess.com 2025-03-31 2025-08-25
DOMAIN api.camtechdrivers.com 2025-03-31 2025-08-25
DOMAIN vidcruitermaster.com 2025-03-31 2025-08-25
IPv4 72.5.42.93 2025-03-31 2025-08-25
DOMAIN quickinterview360.com 2025-02-25 2025-08-25
HASH bfac94bfb53b4c0ac346706b0629635… 2025-01-20 2025-08-25
DOMAIN api.camera-drive.org 2025-01-20 2025-08-25
DOMAIN api.nvidia-release.org 2025-01-16 2025-08-25
HASH 60ec2dbe8cfacdff1d4eb093032b030… 2025-01-05 2025-08-25
HASH b72653bf747b962c67a5999afbc1d91… 2025-01-05 2025-08-25
IPv4 216.74.123.191 2025-01-05 2025-08-25

Related Actors

Related Reports

2025-08-13 • 61% Match
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1218.010 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1573 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004
Shares tags: Lazarus, T1059.003, T1140 • Published within a month
2021-12-02 • 41% Match
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1573.001 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004 #T0865
Shares tags: Lazarus, T1059.003, T1140
« Back