GolangGhost (Windows)

Aliases: BitStep RAT, WeaselStore

First seen
2023-05-01 00:00:00
Malware type
rat
Profile updated
2026-07-07 13:15:01

Targeted industries: financial-services technology-and-telecommunications

Targeted regions: country_code:kr

Context

GolanGhost is a RAT written in Go. It uses C2 to receive commands and exfiltrate data such as browser information targeting especially installed cryptocurrency wallets. It is often used in ClickFix campaigns by North-Korean threat actors.

Reports & references

  • Trend Micro — Russian Infrastructure North Korean Cybercrime (report)
  • Microsoft — Contagious Interview Malware Delivered Through Fake Developer Job Interviews (report)
  • sophos.com — Nickel Alley Strategy Fake It Til You Make It (report)
  • abstract.security — Contagious Interview Evolution Of Vscode And Cursor Tasks Infection Chains (report)
  • www-cdn.anthropic.com — B2A76C6F6992465C09A6F2Fce282F6C0Cea8C200 (report)
  • ESET — Deceptivedevelopment From Primitive Crypto Theft To Sophisticated Ai Based Deception (report)
  • gitlab-com.gitlab.io — North Korean Malware Sept 2025 (report)
  • silentpush.com — Contagious Interview Front Companies (report)
  • recordedfuture.com — Purplebravos Targeting It Software Supply Chain (report)
  • virusbulletin.com — Deceptivedevelopment And North Korean It Workers From Primitive Crypto Theft To Sophisticated Ai Based Deception (report)
  • web-assets.esetstatic.com — Eset Apt Activity Report Q4 2024 Q1 2025 (report)
  • blog.sekoia.io — Clickfake Interview Campaign By Lazarus (report)
  • blog.polyswarm.io — Famous Chollimas Pylangghost (report)
  • abstract.security — Contagious Interview Evolution Of Vs Code And Cursor Tasks Infection Chains Part 2 (report)
  • Cisco Talos — Python Version Of Golangghost Rat (report)
  • wiz.io — North Korean Tradertraitor Crypto Heist (report)
  • any.run — Pylangghost Malware Analysis (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Golangghost (report)

External references