GolangGhost - Comprehensive Threat Intelligence Report
2025-08-25 • Bloo •
GolangGhost is presented as a cross-platform remote access trojan associated with North Korea's Lazarus-linked Famous Chollima activity against cryptocurrency and blockchain job seekers. The infection chain uses fake recruitment sites and bogus video interview setups, where a ClickFix-style error prompt convinces victims to run commands in Windows CMD or macOS Terminal that install the backdoor. The malware and its Python variant PylangGhost can upload and download files, execute OS commands, collect system information, and steal browser data including passwords, cookies, and cryptocurrency wallet information. The excerpt lists multiple C2 domains and U.S.-hosted infrastructure, with targeting concentrated on cryptocurrency professionals and a small number of identified victims, notably in India.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 212.81.47.217 | 2025-06-18 | 2026-01-21 |
| IPv4 | 31.57.243.29 | 2025-06-18 | 2026-01-21 |
| IPv4 | 154.58.204.15 | 2025-06-18 | 2026-01-21 |
| IPv4 | 31.57.243.190 | 2025-06-18 | 2026-01-21 |
| IPv4 | 154.62.226.22 | 2025-03-31 | 2026-01-21 |
| IPv4 | 38.134.148.218 | 2025-03-31 | 2026-01-21 |
| HASH | ba81429101a558418c80857781099e2… | 2025-03-31 | 2025-08-25 |
| HASH | e88700d069a856e1a16c0da317a6f18… | 2025-03-31 | 2025-08-25 |
| HASH | 0cbbf7b2b15b561d47e927c37f6e933… | 2025-03-31 | 2025-08-25 |
| HASH | 6e186ada6371f5b970b25c78f38511a… | 2025-03-31 | 2025-08-25 |
| HASH | d00ca82a32b5e8063492f27dfec225b… | 2025-03-31 | 2025-08-25 |
| HASH | 887189269c3594e1a851eb22f7c174a… | 2025-03-31 | 2025-08-25 |
| HASH | 6289ef57b1772d78da0e54ba4730b6f… | 2025-03-31 | 2025-08-25 |
| HASH | b7b9e7637a42b5db746f1876a2ecb19… | 2025-03-31 | 2025-08-25 |
| HASH | 3fec701b5e8486081c7062590f4ff94… | 2025-03-31 | 2025-08-25 |
| HASH | ef9f49f14149bed09ca9f590d33e07f… | 2025-03-31 | 2025-08-25 |
| HASH | f4b4411e403dd5094eef9c8946522fc… | 2025-03-31 | 2025-08-25 |
| DOMAIN | api.camdriversupport.com | 2025-03-31 | 2025-08-25 |
| DOMAIN | talenthiring360.com | 2025-03-31 | 2025-08-25 |
| DOMAIN | vid-crypto-assess.com | 2025-03-31 | 2025-08-25 |
| DOMAIN | api.camtechdrivers.com | 2025-03-31 | 2025-08-25 |
| DOMAIN | vidcruitermaster.com | 2025-03-31 | 2025-08-25 |
| IPv4 | 72.5.42.93 | 2025-03-31 | 2025-08-25 |
| DOMAIN | quickinterview360.com | 2025-02-25 | 2025-08-25 |
| HASH | bfac94bfb53b4c0ac346706b0629635… | 2025-01-20 | 2025-08-25 |
| DOMAIN | api.camera-drive.org | 2025-01-20 | 2025-08-25 |
| DOMAIN | api.nvidia-release.org | 2025-01-16 | 2025-08-25 |
| HASH | 60ec2dbe8cfacdff1d4eb093032b030… | 2025-01-05 | 2025-08-25 |
| HASH | b72653bf747b962c67a5999afbc1d91… | 2025-01-05 | 2025-08-25 |
| IPv4 | 216.74.123.191 | 2025-01-05 | 2025-08-25 |