Skip to content

Malware

GolangGhost

aka BitStep RAT · WeaselStore

GolanGhost is a RAT written in Go. It uses C2 to receive commands and exfiltrate data such as browser information targeting especially installed cryptocurrency wallets.

GolangGhost, also known as BitStep RAT, WeaselStore, is a Windows malware family operated by WageMole.

Background

GolanGhost is a Go-based RAT that communicates with a C2 to take commands and steal data, including browser information, with a particular focus on installed cryptocurrency wallets.

North Korean threat actors frequently deploy it as part of ClickFix campaigns.


Source: Malpedia (Fraunhofer FKIE).