Skip to content

Malware

GolangGhost

aka BitStep RAT · WeaselStore

GolanGhost is a RAT written in Go. It uses C2 to receive commands and exfiltrate data such as browser information targeting especially installed cryptocurrency wallets.

GolanGhost is a RAT written in Go. It uses C2 to receive commands and exfiltrate data such as browser information targeting especially installed cryptocurrency wallets.

It is often used in ClickFix campaigns by North-Korean threat actors.


Family metadata imported from Malpedia (Fraunhofer FKIE).