Famous Chollima deploying Python version of GolangGhost RAT
ID: 74b09823-f0a5-5b44-81a5-17a6d69b2399
STIX ID: report--74b09823-f0a5-5b44-81a5-17a6d69b2399
Feed Name: Cisco Talos
In May 2025 Cisco Talos published an intelligence report on “PylangGhost,” a Python variant of the GolangGhost RAT deployed by the North Korean-aligned Famous Chollima group. The attackers used fake job/skill-testing sites to trick primarily cryptocurrency and blockchain professionals into executing commands that install the RAT; PylangGhost implements persistence, C2 communication (HTTP with RC4-encrypted payloads), remote shell/file operations and extensive browser/extension credential and cookie theft (including Metamask and other crypto wallets). The report includes module-level analysis, numerous SHA256s, C2 IPs, download and fake-site domains, and recommended detection/mitigation controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
