북한 Lazarus(라자루스) 에서 만든 신형 RAT PyLangGhost RAT 분석-auto.py(2025.8.7)

2025-08-18 Sakai Analysis of the New RAT PyLangGhost RAT Created by North Korean Lazarus - auto.py (2025.8.7)

https://wezard4u.tistory.com/429572

Thumbnail for 북한 Lazarus(라자루스) 에서 만든 신형 RAT PyLangGhost RAT 분석-auto.py(2025.8.7)

A Korean malware analysis attributes the auto.py sample to Lazarus/Famous Chollima and identifies it as part of the PyLangGhost RAT tooling. The script is described as collecting Chrome extension local storage from multiple browser profiles, which could expose wallet, OTP, and other extension data. It also checks for administrator rights, abuses LSASS token impersonation and Windows DPAPI/CNG paths, and derives Chrome v10/v20 master keys to decrypt stored browser passwords. The body lists hashes for the sample and explains how decrypted credentials are written to a log and returned, making the malware relevant to DPRK-linked credential and cryptocurrency theft tracking.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bb794019f8a63966e4a16063dc785fa… 2025-08-06 2025-08-18

Related Reports

« Back