PylangGhost is a Python-based remote access trojan associated with the North Korean threat actor Famous Chollima, also tracked as Wagemole and linked by multiple vendors to the broader Contagious Interview or DeceptiveDevelopment activity cluster. It is primarily used against Windows systems, while related campaigns commonly deploy the closely aligned GolangGhost variant against macOS. The malware has been observed in financially motivated operations targeting cryptocurrency, blockchain, Web3, finance, and technology professionals, including both technical staff and business-facing roles with potential access to wallets, credentials, or company funds.
PylangGhost is modular and supports remote command execution, system profiling, file upload and download, browser data theft, and persistence. Reported module sets include orchestration, configuration, archive handling, command execution, command-and-control communications, and a dedicated stealer component. Its communications use HTTP with RC4-encrypted payloads and integrity checking. On infected hosts it can maintain state, identify victims, and receive additional tasking from its operators.
A core function of PylangGhost is credential and session theft from Chromium-based browsers. It has been reported stealing saved credentials, authentication cookies, session data, and data from more than 80 browser extensions, including cryptocurrency wallet and password-manager extensions. Multiple reports also state that it is engineered to bypass newer Chrome protections, including app-bound credential protection, in order to recover protected browser secrets. This makes it relevant not only for direct credential theft but also for session hijacking and cryptocurrency theft.
Delivery has most prominently occurred through highly tailored fake job interview and recruiter-impersonation campaigns. Victims are lured through professional networking and messaging platforms into fraudulent assessment portals, then manipulated with ClickFix-style prompts that claim a camera, microphone, or driver issue must be fixed by pasting a supplied command into the system. On Windows, this execution chain has been reported to use native scripting and download utilities, unpack a bundled Python runtime, and launch PylangGhost through staged loaders. Some variants have been compiled with Nuitka into native Python extension modules to hinder analysis and signature-based detection.
Beyond direct social-engineering delivery, PylangGhost has also been observed in software supply-chain abuse. Researchers reported malicious npm packages distributing the malware, including campaigns that used JavaScript loaders, runtime decryption, environment profiling, sandbox checks, and staged retrieval through cloud-hosted infrastructure. These supply-chain cases expand the risk from individual job seekers to developers, CI/CD environments, and organizations consuming compromised dependencies.
PylangGhost is best characterized as a Windows-focused RAT used in DPRK-linked financially motivated intrusion campaigns, combining remote access, persistence, defense evasion, credential theft, session theft, and browser-extension harvesting to support theft of cryptocurrency and access to enterprise resources.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SOCRadar has the story: Who Needs a Job? DPRK ClickFake Interview Campaign Drops PylangGhost and GolangGhost RATs
So on Windows, you end up with a remote access Trojan called PyLangGhost, which is written in Python.
"North Korea's abuse of Cloudflare Workers and Pages" published by Kmsec. #FamousChollima, #NPM, #PylangGhost, #DPRK, #CTI
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Famous Chollima... create an entirely fake business... or they impersonate a real one in the cryptocurrency sector... they go looking for potential targets on LinkedIn... The hackers, they're posing as recruiters. They pitch a lucrative new role.
Famous Chollima actors rely on social engineering, posing as potential recruiters to convince targets into a skill assessment, part of a fake interview, and run malicious payloads... reach out to their targets via social media (LinkedIn, Discord, Telegram and Email).
it pastes something from your clipboard into your terminal screen, the Run command, in order to download a piece of malicious code.
The script utilizes native system utilities like PowerShell or curl to fetch a compressed ZIP archive from the attacker's server.
ClickFix instructions included the download of the ZIP file via curl.
It then leverages a Visual Basic Script to silently unpack a Python runtime.
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
Both variants have a util module that is responsible for compressing and decompressing files.
They occasionally create fake front companies or impersonate known ones in the crypto and Web3 industries, and reach out to their targets via social media.
The actors renamed CPython executable to ‘ chost.exe ‘.
The auto module of both variants, actively attempts to elevate its privileges by temporarily impersonating the Windows lsass.exe process to gain SYSTEM-level access, and interacts directly with the Windows Cryptography API to unwrap the browser’s master decryption key.
It is specifically programmed to harvest session data, saved credentials and private keys from widely used cryptocurrency wallets such as MetaMask, Phantom and TronLink, as well as commercial password managers like NordPass.
If you try and copy and paste that link from the web interface, what actually gets copied into your clipboard is something else. And that command, which you then paste in at the command prompt... is downloading from another site entirely.
Both PylangGhost and GolangGhost are built on a highly modular architecture consisting of six interconnected parts. These components include a main orchestrator, a dedicated configuration holder, an archive helper, a command launcher, a command-and-control (C2) communications module and a specialized data stealer.
The script utilizes native system utilities like PowerShell or curl to fetch a compressed ZIP archive from the attacker's server.
142 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan delivered via ClickFix-style social engineering in a fake job interview campaign attributed to Famous Chollima.
A Python-based remote access Trojan delivered via the fake job interview/click-fix flow. It gives attackers a full remote shell, allows file upload/download, access to crypto wallets, password theft, and targets browser extensions used for cryptocurrency wallets.
A Windows counterpart in the same fake recruiter campaign, delivered through deceptive job interview workflows.
A customized Python-based remote access trojan used in the Windows infection chain. It is modular, supports command execution, persistence, C2 communications, and includes a stealer component focused on harvesting browser extension data, credentials, session data, and cryptocurrency wallet private keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.