PylangGhost is a Python-based remote access trojan targeting Windows systems, identified in May 2025 and publicly disclosed in June 2025. It is associated with the North Korean-aligned threat actor Famous Chollima and the Contagious Interview and ClickFake Interview campaigns. It is functionally similar to the Go-based GolangGhost malware, sharing closely related modular architecture and command functionality. Targets include software developers, job seekers, and cryptocurrency, blockchain, and Web3 professionals, including non-technical business personnel. Early observed infections were predominantly in India.
PylangGhost comprises six components covering orchestration, configuration, archive handling, command execution, command-and-control communications, and data theft. It supports remote shell access, system profiling, bidirectional file transfer, browser-data theft, and persistence at user logon through Windows registry autorun configuration. Its command-and-control protocol uses HTTP with RC4-encrypted packets and MD5 checksums. The stealer harvests saved credentials, session cookies, and cryptocurrency-wallet and password-manager extension data from Chromium-based browsers, including Chrome and Edge. It targets more than 80 browser extensions. Later variants incorporate techniques to bypass Chrome App-Bound Encryption and use Nuitka-compiled native Python modules to complicate detection and reverse engineering.
Delivery commonly begins with personalized recruiter impersonation and fraudulent online job assessments. Fabricated camera or microphone failures prompt victims to execute purported troubleshooting commands through ClickFix-style social engineering. The Windows infection chain downloads an archive, uses Visual Basic Script to unpack a bundled Python runtime, and launches the RAT. PylangGhost has also been distributed through malicious npm dependencies, including multi-stage loaders that abuse Cloudflare Pages and Workers. These delivery routes expose both individual job seekers and organizations whose developers execute untrusted recruitment projects or dependencies.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign delivers PylangGhost to Windows users and GolangGhost to macOS users through the same deceptive recruitment process.
So on Windows, you end up with a remote access Trojan called PyLangGhost, which is written in Python.
"North Korea's abuse of Cloudflare Workers and Pages" published by Kmsec. #FamousChollima, #NPM, #PylangGhost, #DPRK, #CTI
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Famous Chollima... create an entirely fake business... or they impersonate a real one in the cryptocurrency sector... they go looking for potential targets on LinkedIn... The hackers, they're posing as recruiters. They pitch a lucrative new role.
Famous Chollima actors rely on social engineering, posing as potential recruiters to convince targets into a skill assessment, part of a fake interview, and run malicious payloads... reach out to their targets via social media (LinkedIn, Discord, Telegram and Email).
it pastes something from your clipboard into your terminal screen, the Run command, in order to download a piece of malicious code.
The script utilizes native system utilities like PowerShell or curl to fetch a compressed ZIP archive from the attacker's server.
ClickFix instructions included the download of the ZIP file via curl.
It then leverages a Visual Basic Script to silently unpack a Python runtime.
This is when the ClickFix attack is launched: the attackers send the victim instructions to paste a command into their computer, which will result in malware installation.
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
Both variants have a util module that is responsible for compressing and decompressing files.
They occasionally create fake front companies or impersonate known ones in the crypto and Web3 industries, and reach out to their targets via social media.
The actors renamed CPython executable to ‘ chost.exe ‘.
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
It is specifically programmed to harvest session data, saved credentials and private keys from widely used cryptocurrency wallets such as MetaMask, Phantom and TronLink, as well as commercial password managers like NordPass.
The group infiltrates job seekers' computer networks, harvesting sensitive information and stealing cryptocurrency; successful infections enable intellectual-property theft.
If you try and copy and paste that link from the web interface, what actually gets copied into your clipboard is something else. And that command, which you then paste in at the command prompt... is downloading from another site entirely.
Both PylangGhost and GolangGhost are built on a highly modular architecture consisting of six interconnected parts. These components include a main orchestrator, a dedicated configuration holder, an archive helper, a command launcher, a command-and-control (C2) communications module and a specialized data stealer.
The multi-step infection chain leads to deployment of various malware families; backdoor access is abused to deliver remote access trojans.
142 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The post links to Atlassian's "Disrupting Contagious Interview" publication and tags #PylangGhost alongside other malware names.
A malware family delivered to targets who complete malicious job assessments in the Contagious Interview campaign.
A remote access trojan delivered via ClickFix-style social engineering in a fake job interview campaign attributed to Famous Chollima.
A Python-based remote access Trojan delivered via the fake job interview/click-fix flow. It gives attackers a full remote shell, allows file upload/download, access to crypto wallets, password theft, and targets browser extensions used for cryptocurrency wallets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.