GolangGhost is a modular, Go-based remote access trojan with integrated information-stealing capabilities. It is the Go variant of the malware family also tracked as FlexibleFerret or WeaselStore; PylangGhost is its closely related Python counterpart. GolangGhost has been deployed against Windows and macOS systems by North Korean threat actors associated with Famous Chollima and the Contagious Interview and ClickFake Interview campaigns. Targets include cryptocurrency, blockchain, and Web3 professionals, encompassing software developers and non-technical business, investment, legal, and advisory personnel.
Delivery commonly begins with personalized recruiter impersonation and fraudulent job assessments. Fake interview portals present fabricated camera or microphone failures and use ClickFix instructions to persuade victims to execute malicious terminal commands disguised as driver installation or troubleshooting. The infection chains download staged payloads and may install the Go toolchain to execute the malware. Persistence is established through Windows autorun configuration or macOS Launch Agents. Recent campaigns deploy GolangGhost primarily to macOS victims and PylangGhost to Windows victims.
GolangGhost supports remote shell execution, system profiling, file upload and download, and browser-data theft. It steals saved credentials, session cookies, and cryptocurrency-wallet and password-manager extension data. On macOS, it retrieves Chrome's stored encryption secret from the Keychain to decrypt browser data. It can also modify Chrome's preference configuration to grant expanded permissions to MetaMask. Its modular components handle command routing, compression, credential theft, and RC4-encrypted HTTP command-and-control communications. macOS variants perform virtual-machine and sandbox checks. Associated infection chains have additionally deployed separate applications that impersonate legitimate system prompts to capture administrator passwords.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The operation delivers GolangGhost, a remote access trojan that can steal browser credentials, collect wallet data, and give attackers control of infected macOS systems.
If you're on a Mac, it's GoLangGhost, which is a remote access Trojan written in Go.
BlockNovas has been observed using video assessments to distribute FROSTYFERRET and GolangGhost using ClickFix-related lures...
ClickFake Interview leverages fake job interview websites to deploy a Go backdoor – GolangGhost – on Windows and macOS environments... This final implant enables remote control and data theft, including browser information exfiltration. | Three variants, FriendlyFerret, FrostyFerret and FlexibleFerret, were deployed during a job interview process on a legitimate website.
Lazarus Group Targets Job Seekers With ClickFix Tactic to Deploy GolangGhost Malware
32 distinct techniques documented for this family, organized by ATT&CK tactic.
the TraderTraitor operators invited the victims to collaborate on a GitHub repository that contained malicious JavaScript packages sourced from npm as dependencies [T1195.001]
Famous Chollima... create an entirely fake business... or they impersonate a real one in the cryptocurrency sector... they go looking for potential targets on LinkedIn... The hackers, they're posing as recruiters. They pitch a lucrative new role.
The attack begins on mainstream professional networks and communication platforms, including LinkedIn, Telegram, Discord and direct email. Posing as recruiters from reputable firms or creating entirely fictitious web companies, the actors reach out to developers and administrators.
it pastes something from your clipboard into your terminal screen, the Run command, in order to download a piece of malicious code.
On macOS, the copied command starts a Bash script that creates a hidden working directory, downloads a fake Intel driver archive, and retrieves the Go compiler needed to run GolangGhost.
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
Both variants have a util module that is responsible for compressing and decompressing files.
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
The campaign also launches a fake macOS application that requests administrator credentials under the guise of an update. Those credentials are sent to attacker-controlled infrastructure
macOS chain included a SwiftUI app that prompts for user credentials.
It is specifically programmed to harvest session data, saved credentials and private keys from widely used cryptocurrency wallets such as MetaMask, Phantom and TronLink, as well as commercial password managers like NordPass.
It is specifically programmed to harvest session data, saved credentials and private keys from widely used cryptocurrency wallets such as MetaMask, Phantom and TronLink, as well as commercial password managers like NordPass.
GolangGhost can use the macOS Keychain command-line utility to retrieve Chrome’s stored master password.
It then applies that secret to decrypt Chrome’s local database, exposing saved browser credentials and cookies that may grant access to online services.
The malware injects broad permissions, including access to active tabs, clipboard writing, web requests, and expanded storage, then assigns them to the MetaMask extension.
On Apple devices, the infection process often installs the primary payload alongside a credential-harvesting helper application built with SwiftUI, which is specifically designed to trick macOS users into surrendering their administrative passwords.
The group infiltrates job seekers' computer networks, harvesting sensitive information and stealing cryptocurrency; successful infections enable intellectual-property theft.
The campaign also launches a fake macOS application that requests administrator credentials under the guise of an update. Those credentials are sent to attacker-controlled infrastructure
macOS chain included a SwiftUI app that prompts for user credentials.
If you try and copy and paste that link from the web interface, what actually gets copied into your clipboard is something else. And that command, which you then paste in at the command prompt... is downloading from another site entirely.
Both PylangGhost and GolangGhost are built on a highly modular architecture consisting of six interconnected parts. These components include a main orchestrator, a dedicated configuration holder, an archive helper, a command launcher, a command-and-control (C2) communications module and a specialized data stealer.
The multi-step infection chain leads to deployment of various malware families; backdoor access is abused to deliver remote access trojans.
170 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The post links to Atlassian's "Disrupting Contagious Interview" publication and tags #GolangGhost alongside other malware names.
A malware family delivered through fraudulent recruitment assessments in the Contagious Interview campaign.
A remote access trojan delivered via ClickFix-style social engineering in a fake job interview campaign attributed to Famous Chollima.
A Go-based remote access Trojan for macOS delivered through the same fake interview/click-fix campaign. It provides remote shell access, supports file transfer, credential theft, and theft from cryptocurrency wallet browser extensions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.