GolangGhost, also known as FlexibleFerret and WeaselStore, is a modular Go-based remote access trojan associated with North Korea-linked Contagious Interview and ClickFake Interview operations, particularly activity attributed to Famous Chollima, also tracked as Wagemole, PurpleBravo, and WaterPlum. It has been used primarily against macOS victims in fake job interview and recruiter-themed campaigns targeting cryptocurrency, Web3, blockchain, AI, and software-development communities, though reporting also describes Windows-focused variants and closely related Python counterparts under the same broader malware family.
The malware is typically delivered through social-engineering workflows that impersonate recruiters, hiring platforms, or technical assessment portals. In prominent campaigns, victims are guided to a fake video-interview step and tricked with a fabricated camera or microphone problem into copying and pasting a malicious terminal command. On macOS, this infection chain downloads staged components, installs persistence via a Launch Agent, and may deploy a companion SwiftUI credential harvester that prompts for administrator credentials under the guise of a software or browser-related fix.
GolangGhost functions as a full-featured RAT and infostealer. Reported capabilities include remote command execution, system profiling, file upload and download, encrypted HTTP-based command-and-control, plugin or modular task loading, and data exfiltration. On macOS it steals browser secrets by retrieving the Chrome Safe Storage secret from the Keychain and using it to decrypt saved browser credentials and cookies. It also harvests data from cryptocurrency wallet and password-manager browser extensions, and has been reported modifying Chrome Secure Preferences to grant elevated permissions to the MetaMask extension, enabling abuse of the trusted browser context. Additional anti-analysis behavior includes virtual-machine and sandbox checks. Some reporting also notes Linux credential-decryption logic within the codebase, indicating broader cross-platform design even when specific campaigns focused on macOS.
Operationally, GolangGhost has been repeatedly linked to financially motivated DPRK activity aimed at theft of cryptocurrency, wallet access, credentials, and other high-value organizational secrets. Victims have included developers as well as business-facing personnel such as advisors, legal, compliance, investment, and operations staff who may have access to wallets, company accounts, or sensitive internal resources.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The operation delivers GolangGhost, a remote access trojan that can steal browser credentials, collect wallet data, and give attackers control of infected macOS systems.
The operation delivers GolangGhost, a remote access trojan that can steal browser credentials, collect wallet data, and give attackers control of infected macOS systems.
Toward the end of the year, researchers documented Famous Chollima’s remote access trojan (RAT) called “GolangGhost” in its source code format, which was frequently used as the final payload in the threat actor’s ClickFix campaigns.
BlockNovas has been observed using video assessments to distribute FROSTYFERRET and GolangGhost using ClickFix-related lures...
Lazarus Group Targets Job Seekers With ClickFix Tactic to Deploy GolangGhost Malware
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Several titles explicitly mention 'VS Code Tasks Abuse,' 'Tracking the VS Code Tasks Infection Vector,' and 'Evolution of VS Code and Cursor Tasks Infection Chains.'
On macOS, the copied command starts a Bash script that creates a hidden working directory, downloads a fake Intel driver archive, and retrieves the Go compiler needed to run GolangGhost.
Several titles explicitly mention 'VS Code Tasks Abuse,' 'Tracking the VS Code Tasks Infection Vector,' and 'Evolution of VS Code and Cursor Tasks Infection Chains.'
Several titles explicitly mention 'VS Code Tasks Abuse,' 'Tracking the VS Code Tasks Infection Vector,' and 'Evolution of VS Code and Cursor Tasks Infection Chains.'
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
Both variants have a util module that is responsible for compressing and decompressing files.
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
The campaign also launches a fake macOS application that requests administrator credentials under the guise of an update. Those credentials are sent to attacker-controlled infrastructure
macOS chain included a SwiftUI app that prompts for user credentials.
It then applies that secret to decrypt Chrome’s local database, exposing saved browser credentials and cookies that may grant access to online services.
GolangGhost can use the macOS Keychain command-line utility to retrieve Chrome’s stored master password.
GolangGhost can use the macOS Keychain command-line utility to retrieve Chrome’s stored master password.
They collect personal information, fingerprint the visitor’s browser and device, block mobile users, show timed assessment questions, and display warnings when candidates switch browser tabs.
The malware also searches for browser extension data associated with cryptocurrency wallets and password managers.
The campaign also launches a fake macOS application that requests administrator credentials under the guise of an update. Those credentials are sent to attacker-controlled infrastructure
170 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS-focused remote access trojan delivered via fake job interview lures. It establishes persistence through a Launch Agent, retrieves Chrome secrets from the macOS Keychain to decrypt stored credentials and cookies, harvests cryptocurrency wallet extension data, and modifies Chrome Secure Preferences to grant broad permissions to the MetaMask extension for abuse.
A named remote access trojan reportedly deployed in a ClickFake job interview campaign attributed in the post to DPRK-linked Famous Chollima.
A Go-based remote access trojan used in the same campaign primarily against macOS, with evidence of code for Windows and Linux as well. It is delivered by bash stagers, persists via a Launch Agent, performs VM/sandbox checks, executes commands, transfers files, steals browser credentials, extracts Chrome secrets from macOS Keychain, supports Linux D-Bus-based browser decryption, and can inject malicious browser preferences to abuse MetaMask.
Named as malware previously used by the Contagious Interview campaign; no further technical details are provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.