GolangGhost is a Go-based remote access trojan associated with North Korean threat activity, especially clusters tracked as Famous Chollima, Wagemole, WaterPlum, and broader Contagious Interview or ClickFake Interview operations. It is also referred to as FlexibleFerret and WeaselStore in reporting that treats the Go and Python implementations as closely related variants, with PylangGhost representing the Python counterpart.
The malware has been used primarily against macOS victims in recruiter-themed social-engineering campaigns targeting cryptocurrency, Web3, blockchain, and related business roles, though some reporting also describes Windows and broader cross-platform lineage. Delivery commonly occurs through fake job interviews, skill assessments, and ClickFix-style lures in which victims are persuaded to paste attacker-supplied commands into a terminal after a fabricated camera or microphone problem. Operators have used recruiter impersonation on professional and messaging platforms and have tailored lures to both technical and non-technical personnel with access to digital assets or sensitive corporate systems.
GolangGhost is modular and supports command execution, file transfer, host profiling, encrypted command-and-control communications, and theft of browser data. Documented capabilities include stealing saved browser credentials, cookies, session data, and data from numerous browser extensions, especially cryptocurrency wallets and password managers. On macOS it has been observed retrieving browser secrets from the Keychain to decrypt Chromium-derived credential stores, harvesting wallet-related extension data, and establishing persistence through Launch Agent mechanisms. Reporting also describes functionality to alter Chromium Secure Preferences to grant elevated permissions to wallet extensions such as MetaMask, enabling abuse of the victim's trusted browser context. Some analyses note Linux credential-decryption logic as part of the codebase, reinforcing its cross-platform design heritage.
Operationally, GolangGhost serves both as an infostealer and as a RAT that maintains ongoing access to infected systems. Its use aligns with financially motivated DPRK operations focused on cryptocurrency theft, credential harvesting, and follow-on access into organizational environments connected to exchanges, DeFi platforms, venture firms, and other digital-asset ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SOCRadar has the story: Who Needs a Job? DPRK ClickFake Interview Campaign Drops PylangGhost and GolangGhost RATs
If you're on a Mac, it's GoLangGhost, which is a remote access Trojan written in Go.
BlockNovas has been observed using video assessments to distribute FROSTYFERRET and GolangGhost using ClickFix-related lures...
ClickFake Interview leverages fake job interview websites to deploy a Go backdoor – GolangGhost – on Windows and macOS environments... This final implant enables remote control and data theft, including browser information exfiltration. | Three variants, FriendlyFerret, FrostyFerret and FlexibleFerret, were deployed during a job interview process on a legitimate website.
Lazarus Group Targets Job Seekers With ClickFix Tactic to Deploy GolangGhost Malware
32 distinct techniques documented for this family, organized by ATT&CK tactic.
the TraderTraitor operators invited the victims to collaborate on a GitHub repository that contained malicious JavaScript packages sourced from npm as dependencies [T1195.001]
Famous Chollima... create an entirely fake business... or they impersonate a real one in the cryptocurrency sector... they go looking for potential targets on LinkedIn... The hackers, they're posing as recruiters. They pitch a lucrative new role.
The attack begins on mainstream professional networks and communication platforms, including LinkedIn, Telegram, Discord and direct email. Posing as recruiters from reputable firms or creating entirely fictitious web companies, the actors reach out to developers and administrators.
it pastes something from your clipboard into your terminal screen, the Run command, in order to download a piece of malicious code.
On macOS, the copied command starts a Bash script that creates a hidden working directory, downloads a fake Intel driver archive, and retrieves the Go compiler needed to run GolangGhost.
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
Both variants have a util module that is responsible for compressing and decompressing files.
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
The campaign also launches a fake macOS application that requests administrator credentials under the guise of an update. Those credentials are sent to attacker-controlled infrastructure
macOS chain included a SwiftUI app that prompts for user credentials.
It is specifically programmed to harvest session data, saved credentials and private keys from widely used cryptocurrency wallets such as MetaMask, Phantom and TronLink, as well as commercial password managers like NordPass.
It is specifically programmed to harvest session data, saved credentials and private keys from widely used cryptocurrency wallets such as MetaMask, Phantom and TronLink, as well as commercial password managers like NordPass.
GolangGhost can use the macOS Keychain command-line utility to retrieve Chrome’s stored master password.
It then applies that secret to decrypt Chrome’s local database, exposing saved browser credentials and cookies that may grant access to online services.
The malware injects broad permissions, including access to active tabs, clipboard writing, web requests, and expanded storage, then assigns them to the MetaMask extension.
On Apple devices, the infection process often installs the primary payload alongside a credential-harvesting helper application built with SwiftUI, which is specifically designed to trick macOS users into surrendering their administrative passwords.
The malware also searches for browser extension data associated with cryptocurrency wallets and password managers.
The campaign also launches a fake macOS application that requests administrator credentials under the guise of an update. Those credentials are sent to attacker-controlled infrastructure
macOS chain included a SwiftUI app that prompts for user credentials.
If you try and copy and paste that link from the web interface, what actually gets copied into your clipboard is something else. And that command, which you then paste in at the command prompt... is downloading from another site entirely.
Both PylangGhost and GolangGhost are built on a highly modular architecture consisting of six interconnected parts. These components include a main orchestrator, a dedicated configuration holder, an archive helper, a command launcher, a command-and-control (C2) communications module and a specialized data stealer.
The script utilizes native system utilities like PowerShell or curl to fetch a compressed ZIP archive from the attacker's server.
170 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan delivered via ClickFix-style social engineering in a fake job interview campaign attributed to Famous Chollima.
A Go-based remote access Trojan for macOS delivered through the same fake interview/click-fix campaign. It provides remote shell access, supports file transfer, credential theft, and theft from cryptocurrency wallet browser extensions.
A macOS-focused remote access trojan delivered via fake job interview lures. It establishes persistence through a Launch Agent, retrieves Chrome secrets from the macOS Keychain to decrypt stored credentials and cookies, harvests cryptocurrency wallet extension data, and modifies Chrome Secure Preferences to grant broad permissions to the MetaMask extension for abuse.
A Go-based remote access trojan used against macOS users in recruiter-themed social engineering attacks. It is part of a modular malware suite with command execution, persistence, C2 communications, and credential and crypto-wallet theft capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.