s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.golangghost

📛 Threat Title

Malware family: GolangGhost

Category: GolangGhost First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.golangghost`. Printable name: GolangGhost.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.golangghost VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.golangghost

IOC database

Type
domain
Value
osx.golangghost
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.golangghost

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.golangghost

References (1)

Remediations (10)

  • web:cyberpress.org

    Malware analytics tools like Cisco Threat Grid identify suspicious binaries, while multi-factor authentication with Cisco Duo adds critical access protection. Enterprise users are advised to apply security controls that block known malicious domains and binaries associated with GolangGhost and PylangGhost.

  • web:cybersecuritynews.com

    North Korean-aligned threat actors from the infamous Famous Chollima group have escalated their cyber operations by deploying a sophisticated new Python-based remote access trojan targeting Windows and macOS users in the cryptocurrency and blockchain sectors. The malware campaign represents a significant evolution of their previously documented GolangGhost RAT, demonstrating the group's ...

  • web:cyberwebspider.com

    North Korean-aligned menace actors from the notorious Well-known Chollima group have escalated their cyber operations by deploying a complicated new Python-based distant entry trojan focusing on Home windows and macOS customers within the cryptocurrency and blockchain sectors. The malware marketing campaign represents a major evolution of their beforehand documented GolangGhost RAT ...

  • web:gbhackers.com

    A North Korean-affiliated threat actor called Famous Chollima has launched a sophisticated RAT campaign against Windows and MacOS devices.

  • web:hivepro.com

    PylangGhost mirrors the capabilities of the GolangGhost RAT, with each variant tailored for different operating systems: Python for Windows environments and Golang for macOS systems. #2 The group behind these campaigns, tracked as Famous Chollima, pursues financial gain through a dual-faceted strategy.

  • web:malpedia.caad.fkie.fraunhofer.de

    GolanGhost is a RAT written in Go. It uses C2 to receive commands and exfiltrate data such as browser information targeting especially installed cryptocurrency wallets. It is often used in ClickFix campaigns by North-Korean threat actors.

  • web:thehackernews.com

    Lazarus Group deploys GolangGhost via fake job interviews using ClickFix, targeting Windows/macOS users with finance roles.

  • web:www.itfunk.org

    Conclusion GolangGhost RAT exemplifies modern macOS threats: silent, modular, and socially engineered. Early detection—by watching for unexpected processes or outbound connections—and swift removal are critical. Running a trusted anti- malware scan and keeping macOS updated remain your best defenses.

  • web:www.linkedin.com

    This technique, known as ClickFix, leads to the stealthy download of malware . On Windows, this installs a VBS script that launches a batch file and then executes GolangGhost .

  • web:www.pcrisk.com

    What kind of malware is GolangGhost ? GolangGhost is a RAT (Remote Access Trojan) targeting Mac operating systems. It is written in the Go programming language (Golang). This malware enables remote access/control over infected machines. It has backdoor and stealer-type functionalities. GolangGhost has been spread through job offer/interview themed ClickFix scams. These campaigns have been ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.