North Korea's Safari: Poaching for Gophers

2026-03-05 Bitso

https://quetzal.bitso.com/p/north-koreas-safari-poaching-for-064

Thumbnail for North Korea's Safari: Poaching for Gophers

Quetzal Team analyzes a Famous Chollima campaign that targets cryptocurrency-themed job or training lures with ClickFix-style social engineering. The infection chain starts with a faux LinkedIn invite to a crypto training site, then a fake webcam driver issue pushes macOS victims to run a command that downloads a Bash stager, a fake Chrome-themed DriverFixerNow app, and a Go-based payload. The Go malware functions as an infostealer and RAT with modules for command execution, data exfiltration, file upload/download, hardware collection, TCP transport, and installation of a fake Chrome instance with malicious extensions. The researchers link the command dictionary to PyLangGhostRAT/GoLangGhostRAT lineage and identify C2 and payload infrastructure including kit-haus[.]net, 144.172.93.88, 157.250.195.237, transfer/upload endpoints, and several SHA-256 hashes. The case is notable because it shows DPRK-linked operators adapting ClickFix delivery and Go malware while reusing recognizable RAT configuration patterns.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 144.172.93.88 2026-03-05 2026-03-23
HASH 97fe475a4177de4e55f3791276fb055… 2026-03-05 2026-03-05
HASH 6ce66f7a2fe04fb451f12bcf4a1ac1c… 2026-03-05 2026-03-05
HASH 0a716920017fba0b70b7295c6d7a067… 2026-03-05 2026-03-05
HASH 72f96d15c4ffb3abadcac3ec4299714… 2026-03-05 2026-03-05
URL https://kit-haus.net/mac-driver 2026-03-05 2026-03-05
DOMAIN kit-haus.net 2026-03-05 2026-03-05
IPv4 157.250.195.237 2026-03-05 2026-03-05

Related Actors

Related Reports

« Back