PylangGhost

Aliases: WeaselStore

First seen
2022-05-15 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 13:17:55

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:ru

Context

PylangGhost, also known as WeaselStore, is a RAT reimplemented in Python from its original Golang version. It is typically used to gain unauthorized remote access and control over compromised systems.

Reports & references

  • Microsoft — Contagious Interview Malware Delivered Through Fake Developer Job Interviews (report)
  • sophos.com — Nickel Alley Strategy Fake It Til You Make It (report)
  • abstract.security — Contagious Interview Evolution Of Vscode And Cursor Tasks Infection Chains (report)
  • ESET — Deceptivedevelopment From Primitive Crypto Theft To Sophisticated Ai Based Deception (report)
  • recordedfuture.com — Purplebravos Targeting It Software Supply Chain (report)
  • virusbulletin.com — Deceptivedevelopment And North Korean It Workers From Primitive Crypto Theft To Sophisticated Ai Based Deception (report)
  • any.run — Lazarus Group Attacks 2025 (report)
  • blog.polyswarm.io — Famous Chollimas Pylangghost (report)
  • abstract.security — Contagious Interview Evolution Of Vs Code And Cursor Tasks Infection Chains Part 2 (report)
  • Cisco Talos — Python Version Of Golangghost Rat (report)
  • malpedia.caad.fkie.fraunhofer.de — Py.Pylangghost (report)
  • any.run — Pylangghost Malware Analysis (report)
  • kmsec.uk — Pylangghost Npm (report)

External references