PyLangGhost RAT: Rising Data Stealer from Lazarus Group Targeting Finance and Technology

2025-08-06 Any Run

https://any.run/cybersecurity-blog/pylangghost-malware-analysis/

Thumbnail for PyLangGhost RAT: Rising Data Stealer from Lazarus Group Targeting Finance and Technology

ANY.RUN analyzes PyLangGhost RAT as a Python-based evolution of GoLangGhostRAT linked in the excerpt to the Lazarus subgroup Famous Chollima. The malware is delivered through targeted ClickFix social engineering against technology, finance, and cryptocurrency personnel, including fake job interviews where victims are told to run a command to fix a bogus camera or microphone issue. The chain downloads a ZIP from 360scanner[.]store, executes a VBScript, launches a renamed Python binary, and runs modules for persistence, C2 communication, command execution, compression, reverse shell access, and credential theft. PyLangGhost targets browser credentials and cryptocurrency wallet extension data from MetaMask, BitKeep, Coinbase Wallet, and Phantom, using Chrome key decryption and privilege-elevation logic. Its raw-IP, non-TLS C2 with RC4/MD5 encryption is technically weak, but the low initial detection rates and wallet-focused theft make it relevant to DPRK financial intrusion monitoring.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 151.243.101.229 2025-08-06 2026-01-21
HASH c7ecf8be40c1e9a9a8c3d148eb2ae2c… 2025-08-06 2025-09-29
HASH bb794019f8a63966e4a16063dc785fa… 2025-08-06 2025-08-18
HASH c4fd45bb8c33a5b0fa5189306eb65fa… 2025-08-06 2025-08-06
HASH a179caf1b7d293f7c14021b80deecd2… 2025-08-06 2025-08-06
HASH ef04a839f60911a5df2408aebd6d9af… 2025-08-06 2025-08-06
IPv4 13.107.246.45 2025-08-06 2025-08-06

Related Actors

Related Reports

« Back