PylangGhost
Aliases: WeaselStore
- First seen
- 2022-05-15 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 13:17:55
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:ru
Context
PylangGhost, also known as WeaselStore, is a RAT reimplemented in Python from its original Golang version. It is typically used to gain unauthorized remote access and control over compromised systems.
Reports & references
- Microsoft — Contagious Interview Malware Delivered Through Fake Developer Job Interviews (report)
- sophos.com — Nickel Alley Strategy Fake It Til You Make It (report)
- abstract.security — Contagious Interview Evolution Of Vscode And Cursor Tasks Infection Chains (report)
- ESET — Deceptivedevelopment From Primitive Crypto Theft To Sophisticated Ai Based Deception (report)
- recordedfuture.com — Purplebravos Targeting It Software Supply Chain (report)
- virusbulletin.com — Deceptivedevelopment And North Korean It Workers From Primitive Crypto Theft To Sophisticated Ai Based Deception (report)
- any.run — Lazarus Group Attacks 2025 (report)
- blog.polyswarm.io — Famous Chollimas Pylangghost (report)
- abstract.security — Contagious Interview Evolution Of Vs Code And Cursor Tasks Infection Chains Part 2 (report)
- Cisco Talos — Python Version Of Golangghost Rat (report)
- malpedia.caad.fkie.fraunhofer.de — Py.Pylangghost (report)
- any.run — Pylangghost Malware Analysis (report)
- kmsec.uk — Pylangghost Npm (report)