PylangGhost is a Python-based remote access trojan associated with the North Korean-aligned threat actor Famous Chollima, also tracked as Wagemole and overlapping with broader Contagious Interview or DeceptiveDevelopment activity. It is primarily used against Windows systems in financially motivated campaigns targeting cryptocurrency, blockchain, Web3, finance, and technology professionals, including job seekers and employees who may have access to wallets, credentials, or corporate resources. The malware is commonly delivered through fake recruiter outreach and fraudulent interview or coding-assessment workflows that use ClickFix-style social engineering to trick victims into executing attacker-supplied commands. It has also been observed distributed through malicious npm packages as part of software supply-chain abuse targeting developers and build environments.
PylangGhost is a modular RAT with functionality for command execution, remote shell access, file upload and download, host profiling, persistence, and encrypted command-and-control communications over HTTP. Reported implementations use multiple coordinated modules for orchestration, configuration, archive handling, command launching, communications, and data theft. On Windows, operators have used staged delivery chains that unpack a bundled Python runtime and execute the malware through scripts or compiled Python components, including variants compiled with Nuitka to hinder analysis and signature-based detection.
A core function of PylangGhost is theft of browser-derived data and cryptocurrency-related secrets. It has been reported stealing saved credentials, cookies, session data, and data from more than 80 browser extensions, including cryptocurrency wallets and password managers. Documented targeting includes wallet extensions such as MetaMask, Phantom, and TronLink, as well as password-management tooling. Multiple reports also state that PylangGhost is engineered to bypass or defeat newer Chrome protections for stored credentials, increasing its effectiveness against Chromium-based browsers. The malware’s role in these campaigns is consistent with DPRK revenue-generation operations focused on cryptocurrency theft and follow-on access to organizational assets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This environment is used to run an execution wrapper that ultimately loads PylangGhost, a highly customized RAT.
So on Windows, you end up with a remote access Trojan called PyLangGhost, which is written in Python.
In May 2025, Cisco Talos identified a Python-based remote access trojan (RAT) we call “PylangGhost,” used exclusively by a North Korean-aligned threat actor.
"North Korea's abuse of Cloudflare Workers and Pages" published by Kmsec. #FamousChollima, #NPM, #PylangGhost, #DPRK, #CTI
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Famous Chollima... create an entirely fake business... or they impersonate a real one in the cryptocurrency sector... they go looking for potential targets on LinkedIn... The hackers, they're posing as recruiters. They pitch a lucrative new role.
The attack begins on mainstream professional networks and communication platforms, including LinkedIn, Telegram, Discord and direct email. Posing as recruiters from reputable firms or creating entirely fictitious web companies, the actors reach out to developers and administrators.
it pastes something from your clipboard into your terminal screen, the Run command, in order to download a piece of malicious code.
The script utilizes native system utilities like PowerShell or curl to fetch a compressed ZIP archive from the attacker's server.
ClickFix instructions included the download of the ZIP file via curl.
It then leverages a Visual Basic Script to silently unpack a Python runtime.
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
Both variants have a util module that is responsible for compressing and decompressing files.
The actors renamed CPython executable to ‘ chost.exe ‘.
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
It is specifically programmed to harvest session data, saved credentials and private keys from widely used cryptocurrency wallets such as MetaMask, Phantom and TronLink, as well as commercial password managers like NordPass.
If you try and copy and paste that link from the web interface, what actually gets copied into your clipboard is something else. And that command, which you then paste in at the command prompt... is downloading from another site entirely.
Both PylangGhost and GolangGhost are built on a highly modular architecture consisting of six interconnected parts. These components include a main orchestrator, a dedicated configuration holder, an archive helper, a command launcher, a command-and-control (C2) communications module and a specialized data stealer.
The script utilizes native system utilities like PowerShell or curl to fetch a compressed ZIP archive from the attacker's server.
142 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python-based remote access Trojan delivered via the fake job interview/click-fix flow. It gives attackers a full remote shell, allows file upload/download, access to crypto wallets, password theft, and targets browser extensions used for cryptocurrency wallets.
A Windows counterpart in the same fake recruiter campaign, delivered through deceptive job interview workflows.
A customized Python-based remote access trojan used in the Windows infection chain. It is modular, supports command execution, persistence, C2 communications, and includes a stealer component focused on harvesting browser extension data, credentials, session data, and cryptocurrency wallet private keys.
A named remote access trojan reportedly deployed in a ClickFake job interview campaign attributed in the post to DPRK-linked Famous Chollima.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.