North Korea's Safari: Poaching for Gophers
2026-03-05 • Bitso •
https://quetzal.bitso.com/p/north-koreas-safari-poaching-for-064
Quetzal Team analyzes a Famous Chollima campaign that targets cryptocurrency-themed job or training lures with ClickFix-style social engineering. The infection chain starts with a faux LinkedIn invite to a crypto training site, then a fake webcam driver issue pushes macOS victims to run a command that downloads a Bash stager, a fake Chrome-themed DriverFixerNow app, and a Go-based payload. The Go malware functions as an infostealer and RAT with modules for command execution, data exfiltration, file upload/download, hardware collection, TCP transport, and installation of a fake Chrome instance with malicious extensions. The researchers link the command dictionary to PyLangGhostRAT/GoLangGhostRAT lineage and identify C2 and payload infrastructure including kit-haus[.]net, 144.172.93.88, 157.250.195.237, transfer/upload endpoints, and several SHA-256 hashes. The case is notable because it shows DPRK-linked operators adapting ClickFix delivery and Go malware while reusing recognizable RAT configuration patterns.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 144.172.93.88 | 2026-03-05 | 2026-03-23 |
| HASH | 97fe475a4177de4e55f3791276fb055… | 2026-03-05 | 2026-03-05 |
| HASH | 6ce66f7a2fe04fb451f12bcf4a1ac1c… | 2026-03-05 | 2026-03-05 |
| HASH | 0a716920017fba0b70b7295c6d7a067… | 2026-03-05 | 2026-03-05 |
| HASH | 72f96d15c4ffb3abadcac3ec4299714… | 2026-03-05 | 2026-03-05 |
| URL | https://kit-haus.net/mac-driver | 2026-03-05 | 2026-03-05 |
| DOMAIN | kit-haus.net | 2026-03-05 | 2026-03-05 |
| IPv4 | 157.250.195.237 | 2026-03-05 | 2026-03-05 |