TF-MAL-osx.golangghost
📛 Threat Title
Malware family: GolangGhost
Description
ThreatFox malware family `osx.golangghost`. Printable name: GolangGhost.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.golangghost
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.golangghost
IOC database
- Type
- domain
- Value
osx.golangghost- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.golangghost
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.golangghost
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberpress.org
Malware analytics tools like Cisco Threat Grid identify suspicious binaries, while multi-factor authentication with Cisco Duo adds critical access protection. Enterprise users are advised to apply security controls that block known malicious domains and binaries associated with GolangGhost and PylangGhost.
-
web:cybersecuritynews.com
North Korean-aligned threat actors from the infamous Famous Chollima group have escalated their cyber operations by deploying a sophisticated new Python-based remote access trojan targeting Windows and macOS users in the cryptocurrency and blockchain sectors. The malware campaign represents a significant evolution of their previously documented GolangGhost RAT, demonstrating the group's ...
-
web:cyberwebspider.com
North Korean-aligned menace actors from the notorious Well-known Chollima group have escalated their cyber operations by deploying a complicated new Python-based distant entry trojan focusing on Home windows and macOS customers within the cryptocurrency and blockchain sectors. The malware marketing campaign represents a major evolution of their beforehand documented GolangGhost RAT ...
-
web:gbhackers.com
A North Korean-affiliated threat actor called Famous Chollima has launched a sophisticated RAT campaign against Windows and MacOS devices.
-
web:hivepro.com
PylangGhost mirrors the capabilities of the GolangGhost RAT, with each variant tailored for different operating systems: Python for Windows environments and Golang for macOS systems. #2 The group behind these campaigns, tracked as Famous Chollima, pursues financial gain through a dual-faceted strategy.
-
web:malpedia.caad.fkie.fraunhofer.de
GolanGhost is a RAT written in Go. It uses C2 to receive commands and exfiltrate data such as browser information targeting especially installed cryptocurrency wallets. It is often used in ClickFix campaigns by North-Korean threat actors.
-
web:thehackernews.com
Lazarus Group deploys GolangGhost via fake job interviews using ClickFix, targeting Windows/macOS users with finance roles.
-
web:www.itfunk.org
Conclusion GolangGhost RAT exemplifies modern macOS threats: silent, modular, and socially engineered. Early detection—by watching for unexpected processes or outbound connections—and swift removal are critical. Running a trusted anti- malware scan and keeping macOS updated remain your best defenses.
-
web:www.linkedin.com
This technique, known as ClickFix, leads to the stealthy download of malware . On Windows, this installs a VBS script that launches a batch file and then executes GolangGhost .
-
web:www.pcrisk.com
What kind of malware is GolangGhost ? GolangGhost is a RAT (Remote Access Trojan) targeting Mac operating systems. It is written in the Go programming language (Golang). This malware enables remote access/control over infected machines. It has backdoor and stealer-type functionalities. GolangGhost has been spread through job offer/interview themed ClickFix scams. These campaigns have been ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.