PyLangGhost RAT: Rising Data Stealer from Lazarus Group Targeting Finance and Technology
2025-08-06 • Any Run •
https://any.run/cybersecurity-blog/pylangghost-malware-analysis/
ANY.RUN analyzes PyLangGhost RAT as a Python-based evolution of GoLangGhostRAT linked in the excerpt to the Lazarus subgroup Famous Chollima. The malware is delivered through targeted ClickFix social engineering against technology, finance, and cryptocurrency personnel, including fake job interviews where victims are told to run a command to fix a bogus camera or microphone issue. The chain downloads a ZIP from 360scanner[.]store, executes a VBScript, launches a renamed Python binary, and runs modules for persistence, C2 communication, command execution, compression, reverse shell access, and credential theft. PyLangGhost targets browser credentials and cryptocurrency wallet extension data from MetaMask, BitKeep, Coinbase Wallet, and Phantom, using Chrome key decryption and privilege-elevation logic. Its raw-IP, non-TLS C2 with RC4/MD5 encryption is technically weak, but the low initial detection rates and wallet-focused theft make it relevant to DPRK financial intrusion monitoring.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 151.243.101.229 | 2025-08-06 | 2026-01-21 |
| HASH | c7ecf8be40c1e9a9a8c3d148eb2ae2c… | 2025-08-06 | 2025-09-29 |
| HASH | bb794019f8a63966e4a16063dc785fa… | 2025-08-06 | 2025-08-18 |
| HASH | c4fd45bb8c33a5b0fa5189306eb65fa… | 2025-08-06 | 2025-08-06 |
| HASH | a179caf1b7d293f7c14021b80deecd2… | 2025-08-06 | 2025-08-06 |
| HASH | ef04a839f60911a5df2408aebd6d9af… | 2025-08-06 | 2025-08-06 |
| IPv4 | 13.107.246.45 | 2025-08-06 | 2025-08-06 |