{"id":7011,"date":"2025-06-18T07:35:40","date_gmt":"2025-06-18T07:35:40","guid":{"rendered":"http:\/\/localhost\/?p=7011"},"modified":"2025-06-18T07:35:40","modified_gmt":"2025-06-18T07:35:40","slug":"famous-chollima-deploying-python-version-of-golangghost-rat","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=7011","title":{"rendered":"Famous Chollima deploying Python version of GolangGhost RAT"},"content":{"rendered":"<h2>Security Update News<\/h2>\n<h3>Update Information<\/h3>\n<table style=\"width:100%; border-collapse: collapse; margin-bottom: 20px;\">\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Title<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">Famous Chollima deploying Python version of GolangGhost RAT<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Update ID<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">TALOSBLOG:9AD0D911B5B851CCE8C8429BC9427AA5<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Type<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">talosblog<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Published<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">2025-06-18T10:00:44<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Last Updated<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">2025-06-18T10:00:44<\/td>\n<\/tr>\n<\/table>\n<h3>Security Impact<\/h3>\n<table style=\"width:100%; border-collapse: collapse; margin-bottom: 20px;\">\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">CVSS Score<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">0.0<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Severity<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd; color: #666666; font-weight: bold;\">NONE<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Attack Vector<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\"><\/td>\n<\/tr>\n<\/table>\n<h3>Affected CVEs<\/h3>\n<div style=\" padding: 15px; border: 1px solid #ddd; margin-bottom: 20px;\">\n<ul style=\"margin: 0; padding-left: 20px;\">\n<\/ul>\n<\/div>\n<h3>Update Details<\/h3>\n<div style=\"; padding: 15px; border-left: 4px solid #4CAF50; margin-bottom: 20px;\">\n* In May 2025, Cisco Talos identified a Python-based remote access trojan (RAT) we call &#8220;PylangGhost,&#8221; used exclusively by a North Korean-aligned threat actor. PylangGhost is functionally similar to the previously documented GolangGhost RAT, sharing many of the same capabilities.<br \/>  * In recent campaigns, the threat actor _Famous Chollima_ &#8212; potentially made up of multiple groups &#8212; has been using a Python-based version of their trojan to target Windows systems, while continuing to deploy a Golang-based version for MacOS users. Linux users are not targeted in these latest campaigns.<br \/>  * The attacks are targeting employees with experience in cryptocurrency and blockchain technologies.<br \/>  * Based on open-source intelligence, only a small number of users, predominantly in India, are affected. Cisco product telemetry does not indicate that there are any affected Cisco users.<\/p>\n<p>* * *<\/p>\n<p>![Famous Chollima deploying Python version of GolangGhost RAT](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/06\/image-2.jpeg)<\/p>\n<p>Since mid-2024, the threat actor group _Famous Chollima (aka Wagemole)_, a North Korean-aligned threat actor, has been very active through several well-documented campaigns. These campaigns include using variants of Contagious Interview (aka DeceptiveDevelopment) and creating fake job advertisements and skill-testing pages. In the latter, users are instructed to copy and paste (ClickFix) a malicious command line in order to install drivers necessary to conduct the final skill-testing stage.<\/p>\n<p>Toward the end of the year, researchers documented Famous Chollima&#8217;s remote access trojan (RAT) called &#8220;GolangGhost&#8221; in its source code format, which was frequently used as the final payload in the threat actor&#8217;s ClickFix campaigns.<\/p>\n<p>In May 2025, Cisco Talos discovered threat actors starting to deploy a functionally equivalent Python variant of GolangGhost trojan, which we call &#8220;PylangGhost.&#8221;<\/p>\n<p>## Fake job interview sites mislead users to PylangGhost infection<\/p>\n<p>Famous Chollima seek financial benefit using a two-pronged approach: first, by creating fake employers for the purpose of jobseekers exposing their personal information, and second by deploying fake employees as workers in targeted victim companies.<\/p>\n<p>This blog focuses on the first method, where real software engineers, marketing employees, designers and other workers are targeted by fake recruiters and instructed to visit skill-testing pages in order to move forward with their application.<\/p>\n<p>Based on the advertised positions, it is clear that the Famous Chollima is broadly targeting individuals with previous experience in cryptocurrency and blockchain technologies. The skill-testing sites attempt to impersonate real companies such as Coinbase, Archblock, Robinhood, Parallel Studios, Uniswap and others, which helps with the targeting.<\/p>\n<p>![Famous Chollima deploying Python version of GolangGhost RAT](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/06\/ChollimaFigure1-01-1.png)Figure 1. Examples of initial fake job sites.<\/p>\n<p>Each target is sent an invite code to visit a testing website where, depending on the position, they are instructed to enter their details and answer several questions to test their experience and skills. The sites are created using the React framework and have very similar visual designs, no matter the type of position.<\/p>\n<p>![Famous Chollima deploying Python version of GolangGhost RAT](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/06\/data-src-image-a17be5ae-26e9-417a-9fef-bfc518153aac.png) __Figure 2. Example of questions asked for an illegitimate Business Development Manager position at Robinhood.__<\/p>\n<p>Once the user answers all the questions and provides personal details, the site displays an invitation to record a video for the interviewer, recommending that the user request camera access by pressing a button.<\/p>\n<p>![Famous Chollima deploying Python version of GolangGhost RAT](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/06\/data-src-image-7e93dffd-d191-4d84-abea-0fe861b1dcf0.png) __Figure 3. A camera setup page displayed once questions are answered.__<\/p>\n<p>Finally, when the user requests camera, the site displays the instructions for the user to copy, paste and execute a command to allegedly install the required video drivers, if the OS is supported. When Talos used Windows and MacOS test systems, the instructions were shown as seen in Figure 4 and 5. The Linux test system led to another error message, without any instructions to download and install the payload.<\/p>\n<p>![Famous Chollima deploying Python version of GolangGhost RAT](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/06\/data-src-image-628846bb-0b5d-4677-9edb-0cf83cd30d9e.png)Figure 4. Windows instructions to copy, paste and execute a malicious command. ![Famous Chollima deploying Python version of GolangGhost RAT](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/06\/data-src-image-b690f129-55cf-4328-b08d-107a3dbd05d4.jpeg)Figure 5. MacOS instructions to copy, paste and execute a malicious command.<\/p>\n<p>Instructions for downloading the alleged fix are different based on the browser fingerprinting, and also given in appropriate shell language for the OS: PowerShell or Command Shell for Windows, and Bash for MacOS.<\/p>\n<p>![Famous Chollima deploying Python version of GolangGhost RAT](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/06\/ChollimaFigure1-02.png)__Figure 6. Command Shell, PowerShell or Bash instructions to download a payload.__<\/p>\n<p>## PylangGhost &#8211; Python variant of GolangGhost<\/p>\n<p>As the Golang variant of the RAT is already well-documented, this blog focuses on the Python version and the similarities between the two. The initial stage consists of a command line which the fake webpage tells the unsuspecting user to copy, paste and execute.<\/p>\n<p>The command line uses either PowerShell Invoke-Webrequest or curl to download a ZIP file containing the PylangGhost modules as well as Visual Basic Script file. This script is responsible for unzipping the Python library stored in the &#8220;lib.zip file&#8221; and launching the trojan by running a renamed Python interpreter using the file &#8220;nvidia.py&#8221; as the Python program to run.<\/p>\n<p>![Famous Chollima deploying Python version of GolangGhost RAT](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/06\/data-src-image-64d6d9cf-30fa-4f18-af58-41b735dc04e4.png)Figure 7. The first stage simply unzips a Python distribution library and launches the RAT.<\/p>\n<p>PylangGhost consists of six well-structured Python modules. It is not clear to Talos why the threat actors decided to create two variants using a different programming language, or which was created first. Based on the comments in the code, it is unlikely that the threat actors used a large language model (LLM) to help rewrite the code for Python. One of the strings in the configuration module file (&#8220;config.py&#8221;) indicates that the Python version is 1.0, while the appropriate configuration variable in the Golang version indicates that the version is 2.0. However, Talos cannot definitively conclude that those two version numbers are comparable.<\/p>\n<p>The execution starts with the file &#8220;nvidia.py&#8221;, which performs several tasks: It creates a registry value to launch the RAT every time user logs onto the system, generates a GUID for the system to be used in communication with command and control (C2) server, connects to the C2 server and enters the command loop for communication with the server.<\/p>\n<p>![Famous Chollima deploying Python version of GolangGhost RAT](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/06\/data-src-image-d28fc998-31ac-46a7-9973-4c597cac0361.png) __Figure 8. &#8220;nvidia.py&#8221; executes the main loop for communication with the C2 server__<\/p>\n<p>The configuration file &#8220;config.py&#8221; specifies the commands that can be received from the server, which are identical to the commands previously documented in the Golang version of the RAT. These commands enable remote control the infected system and the theft of cookies and credentials from over 80 browser extensions, including password managers and cryptocurrency wallets, including Metamask, 1Password, NordPass, Phantom, Bitski, Initia, TronLink and MultiverseX.<\/p>\n<p>The command handling module, &#8220;command.py&#8221;, defines function handlers and handles the commands received from the C2 server.<\/p>\n<p>Command | Functionality  <br \/>&#8212;|&#8212;  <br \/>qwer | COMMAND_INFORMATION &#8211; collect information about the infected system, username, OS version etc  <br \/>asdf | COMMAND_FILE_UPLOAD &#8211; file upload  <br \/>zxcv | COMMAND_FILE_DOWNLOAD &#8211; file download  <br \/>vbcx | COMMAND_OS_SHELL &#8211; launch an OS shell for remote access and control of the infected system  <br \/>ghdj | COMMAND_WAIT &#8211; sleep for a number of seconds specified by the C2 server  <br \/>r4ys | COMMAND_AUTO \\- browser information stealing command  <br \/>89io | AUTO_CHROME_GATHER_COMMAND &#8211; subcommand of the browser information stealer command  <br \/>gi%# | AUTO_CHROME_COOKIE_COMMAND &#8211; subcommand of the browser information stealer command  <br \/>dghh | COMMAND_EXIT  <\/p>\n<p>_Table 1. Commands and functionalities._<\/p>\n<p>The module &#8220;auto.py&#8221; contains the functionality for stealing the stored browser credentials and session cookies, as well as collecting data from various browser extensions.<\/p>\n<p>&#8220;Api.py&#8221; is responsible for implementing the communications protocol with the C2 server, using RC4 encryption to encrypt packets over otherwise unencrypted HTTP used while communicating with the C2 server. The data in a HTTP packet is encrypted with RC4 algorithm, but the encryption key is also sent within the packet structure. The packet begins with 16 bytes of MD5 checksum for the rest of the packet, for verification of data integrity, followed by 128 bytes containing the RC4 encryption key, followed by an encrypted data blob.<\/p>\n<p>Finally, &#8220;util.py&#8221; handles the compression and decompression of files.<\/p>\n<p>## Comparison of Python and Golang modules<\/p>\n<p>To assess the similarity between the two versions, Talos compares the names of the modules written in different languages as well as their functionality. The structure, the naming conventions and the function names are very similar, which indicates that the developers of the different versions either worked closely together or are the same person.<\/p>\n<p>Module | Python name | Golang name  <br \/>&#8212;|&#8212;|&#8212;  <br \/>Main function module | nvidia.py | cloudfixer.go  <br \/>Configuration module | config.py | config\/constans.go  <br \/>Main command loop | nvidia.py | core\/loop.go  <br \/>Command handlers | command.py | core\/loop.go  <br \/>Browser Stealer functionality | auto.py | auto\/* modules  <br \/>File compression | util.py | util\/compress.go  <br \/>Base64 message encoding | command.py | command\/stackcmd.go  <br \/>Duplicate process check | nvidia.py | instance\/check.go  <br \/>Communications protocol | api.py | transport\/htxp.go  <\/p>\n<p>_Table 2. Comparison of Python and Golang RAT module names. _<\/p>\n<p>## Coverage<\/p>\n<p>Ways our customers can detect and block this threat are listed below.<\/p>\n<p>![Famous Chollima deploying Python version of GolangGhost RAT](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/06\/data-src-image-f7908128-480a-4cb9-a1c2-a25317115dbd.png)<\/p>\n<p> _Cisco Secure Endpoint_ (formerly AMP for Endpoints) is ideally suited to prevent the execution of the malware detailed in this post. Try Secure Endpoint for free _here._<\/p>\n<p> _Cisco Secure Email_ (formerly Cisco Email Security) can block malicious emails sent by threat actors as part of their campaign. You can try Secure Email for free _here_.<\/p>\n<p> _Cisco Secure Firewall_ (formerly Next-Generation Firewall and Firepower NGFW) appliances such as _Threat Defense Virtual_, _Adaptive Security Appliance_ and _Meraki MX_ can detect malicious activity associated with this threat.<\/p>\n<p> _Cisco Secure Network\/Cloud Analytics_ (Stealthwatch\/Stealthwatch Cloud) analyzes network traffic automatically and alerts users of potentially unwanted activity on every connected device.<\/p>\n<p> _Cisco Secure Malware Analytics_ (Threat Grid) identifies malicious binaries and builds protection into all Cisco Secure products.<\/p>\n<p> _Cisco Secure Access_ is a modern cloud-delivered Security Service Edge (SSE) built on Zero Trust principles. Secure Access provides seamless transparent and secure access to the internet, cloud services or private application no matter where your users work. Please contact your Cisco account representative or authorized partner if you are interested in a free trial of Cisco Secure Access.<\/p>\n<p> _Umbrella_, Cisco&#8217;s secure internet gateway (SIG), blocks users from connecting to malicious domains, IPs and URLs, whether users are on or off the corporate network.<\/p>\n<p> _Cisco Secure Web Appliance_ (formerly Web Security Appliance) automatically blocks potentially dangerous sites and tests suspicious sites before users access them.<\/p>\n<p>Additional protections with context to your specific environment and threat data are available from the _Firewall Management Center_.<\/p>\n<p> _Cisco Duo_ provides multi-factor authentication for users to ensure only those authorized are accessing your network.<\/p>\n<p>Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on _Snort.org_.<\/p>\n<p>ClamAV detections available for this threat:<\/p>\n<p>    Win.Backdoor.PyChollima-10045389-0<br \/>    Win.Backdoor.PyChollima-10045388-0<br \/>    Win.Backdoor.PyChollima-10045387-0<br \/>    Win.Backdoor.PyChollima-10045386-0<br \/>    Win.Backdoor.PyChollima-10045385-0<br \/>    Win.Backdoor.PyChollima-10045384-0<\/p>\n<p>## IOCs<\/p>\n<p>The IOCs can also be found in our GitHub repository here.<\/p>\n<p>#### SHA256 __<\/p>\n<p>    a206ea9b415a0eafd731b4eec762a5b5e8df8d9007e93046029d83316989790a &#8211; auto.py\u00a0\u00a0<br \/>    c2137cd870de0af6662f56c97d27b86004f47b866ab27190a97bde7518a9ac1b &#8211; auto.py\u00a0\u00a0<br \/>    0d14960395a9d396d413c2160570116e835f8b3200033a0e4e150f5e50b68bec &#8211; api.py\u00a0<br \/>    8ead05bb10e6ab0627fcb3dd5baa59cdaab79aa3522a38dad0b7f1bc0dada10a &#8211; api.py\u00a0<br \/>    5273d68b3aef1f5ebf420b91d66a064e34c4d3495332fd492fecb7ef4b19624e &#8211; nvidia.py\u00a0<br \/>    267009d555f59e9bf5d82be8a046427f04a16d15c63d9c7ecca749b11d8c8fc3 &#8211; nvidia.py\u00a0<br \/>    7ac3ffb78ae1d2d9b5d3d336d2a2409bd8f2f15f5fb371a1337dd487bd471e32 &#8211; nvidia.py\u00a0<br \/>    b7ab674c5ce421d9233577806343fc95602ba5385aa4624b42ebd3af6e97d3e5 &#8211; util.py\u00a0<br \/>    fb5362c4540a3cbff8cb1c678c00cc39801dc38151edc4a953e66ade3e069225 &#8211; util.py\u00a0<br \/>    d029be4142fca334af8fe0f5f467a0e0e1c89d3b881833ee53c1e804dc912cfd &#8211; command.py\u00a0<br \/>    b8402db19371db55eebea08cf1c1af984c3786d03ff7eae954de98a5c1186cee &#8211; command.py\u00a0<br \/>    1f482ce7e736a8541cc16e3e80c7890d13fb1f561ae38215a98a75dce1333cee &#8211; config.py\u00a0<br \/>    ed170975e3fd03440360628f447110e016f176a44f951fcf6bc8cdb47fbd8e0e &#8211; config.py\u00a0<br \/>    929c69827cd2b03e7b03f9a53c08268ab37c29ac4bd1b23425f66a62ad74a13b &#8211; config.py\u00a0<br \/>    127406b838228c39b368faa9d6903e7e712105b5ad8f43a987a99f7b10c29780 &#8211; config.py\u00a0<br \/>    0ec9d355f482a292990055a9074fdabdb75d72630b920a61bdf387f2826f5385 &#8211; update.vbs\u00a0<br \/>    c2d2320ae43aaa0798cbcec163a0265cba511f8d42d90d45cd49a43fe1c40be6 &#8211; update.vbs\u00a0<br \/>    e7c2b524f5cb0761a973accc9a4163294d678f5ce6aca73a94d4e106f4c8fea4 &#8211; nvidiaRelease.zip\u00a0<br \/>    28198494f0ed5033085615a57573e3d748af19e4bd6ea215893ebeacf6e576df &#8211; vdriverWin.zip\u00a0<br \/>    fc71a1df2bb4ac2a1cc3f306c3bdf0d754b9fab6d1ac78e4eceba5c6e7aee85d &#8211; nvidiaRelease.zip\u00a0<br \/>    d3500266325555c9e777a4c585afc05dfd73b4cbe9dba741c5876593b78059fd &#8211; nvidiaRelease.zip\u00a0<\/p>\n<p>#### C2 servers __<\/p>\n<p>    hxxp[:\/\/]31[.]57[.]243[.]29:8080\u00a0<br \/>    hxxp[:\/\/]154[.]58[.]204[.]15:8080\u00a0<br \/>    hxxp[:\/\/]212[.]81[.]47[.]217:8080\u00a0<br \/>    hxxp[:\/\/] 31[.]57[.]243[.]190:8080<\/p>\n<p>#### Download host names __<\/p>\n<p>    api[.]quickcamfix[.]online\u00a0\u00a0\u00a0<br \/>    api[.]auto-fixer[.]online\u00a0\u00a0\u00a0<br \/>    api[.]quickdriverupdate[.]online\u00a0\u00a0\u00a0<br \/>    api[.]camtuneup[.]online\u00a0\u00a0\u00a0<br \/>    api[.]driversofthub[.]online\u00a0\u00a0\u00a0<br \/>    api[.]drive-release[.]cloud\u00a0\u00a0\u00a0<br \/>    api[.]vcamfixer[.]online\u00a0\u00a0\u00a0<br \/>    api[.]nvidia-drive[.]cloud\u00a0\u00a0\u00a0<br \/>    api[.]nvidia-release[.]us\u00a0\u00a0\u00a0<br \/>    api[.]autodriverfix[.]online\u00a0\u00a0\u00a0<br \/>    api[.]camdriversupport[.]com\u00a0\u00a0\u00a0<br \/>    api[.]smartdriverfix[.]cloud\u00a0\u00a0\u00a0<br \/>    api[.]drivercams[.]cloud\u00a0\u00a0\u00a0<br \/>    api[.]camtechdrivers[.]com\u00a0\u00a0\u00a0<br \/>    api[.]web-cam[.]cloud\u00a0\u00a0\u00a0<br \/>    api[.]camera-drive[.]org\u00a0\u00a0\u00a0<br \/>    api[.]nvidia-release[.]org\u00a0<br \/>    api[.]fixdiskpro[.]online\u00a0<br \/>    api[.]autocamfixer[.]online<\/p>\n<p>#### Fake job interview host names __<\/p>\n<p>#### <\/p>\n<p>    krakenhire[.]com\u00a0\u00a0<br \/>    yuga[.]skillquestions[.]com\u00a0\u00a0<br \/>    uniswap[.]speakure[.]com\u00a0\u00a0<br \/>    doodles[.]skillquestions[.]com\u00a0\u00a0<br \/>    www[.]hireviavideo[.]com\u00a0\u00a0<br \/>    kraken[.]livehiringpro[.]com\u00a0\u00a0<br \/>    quiz-nest[.]com\u00a0\u00a0<br \/>    www[.]smartvideohire[.]com\u00a0\u00a0<br \/>    www[.]talent-hiringstep[.]com\u00a0\u00a0<br \/>    provevidskillcheck[.]com\u00a0\u00a0<br \/>    skill[.]vidintermaster[.]com\u00a0\u00a0<br \/>    digitaltalent[.]review\u00a0\u00a0<br \/>    robinhood[.]ecareerscan[.]com\u00a0\u00a0<br \/>    evalswift[.]com\u00a0\u00a0<br \/>    livetalentpro[.]com\u00a0\u00a0<br \/>    quantumnodespro[.]com\u00a0\u00a0<br \/>    evalassesso[.]com\u00a0\u00a0<br \/>    parallel[.]eskillora[.]com\u00a0\u00a0<br \/>    coinbase[.]talentmonitoringtool[.]com\u00a0\u00a0<br \/>    uniswap[.]testforhire[.]com\u00a0\u00a0<br \/>    coinbase[.]talenthiringtool[.]com\u00a0\u00a0<br \/>    crosstheages[.]skillence360[.]com\u00a0<br \/>    parallel [.] eskillprov [.] com\u00a0<br \/>    assesstrack [.] com\u00a0<br \/>    coinbase [.] talentmonitoringtool [.] com\u00a0<br \/>    talent-hiringtalk[.]com\u00a0<br \/>    uniswap[.]prehireiq[.]com\u00a0<br \/>    fast-video-recording[.]com\n<\/div>\n<p><a href=\"https:\/\/blog.talosintelligence.com\/python-version-of-golangghost-rat\/\" target=\"_blank\" style=\"display: inline-block; color: white; padding: 10px 20px; text-decoration: none; border-radius: 4px;\">View Advisory Details<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security Update News Update Information Title Famous Chollima deploying Python version of GolangGhost RAT Update ID TALOSBLOG:9AD0D911B5B851CCE8C8429BC9427AA5 Type talosblog Published 2025-06-18T10:00:44 Last Updated 2025-06-18T10:00:44 Security&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,34,12,13,33,7,69,11,5],"class_list":["post-7011","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-cvss-00","tag-exploit","tag-news","tag-none","tag-security","tag-talosblog","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Famous Chollima deploying Python version of GolangGhost RAT - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=7011\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Famous Chollima deploying Python version of GolangGhost RAT - zero redgem\" \/>\n<meta property=\"og:description\" content=\"Security Update News Update Information Title Famous Chollima deploying Python version of GolangGhost RAT Update ID TALOSBLOG:9AD0D911B5B851CCE8C8429BC9427AA5 Type talosblog Published 2025-06-18T10:00:44 Last Updated 2025-06-18T10:00:44 Security...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=7011\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-18T07:35:40+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=7011#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=7011\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Famous Chollima deploying Python version of GolangGhost RAT\",\"datePublished\":\"2025-06-18T07:35:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=7011\"},\"wordCount\":2546,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-0.0\",\"exploit\",\"news\",\"NONE\",\"Security\",\"talosblog\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=7011#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=7011\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=7011\",\"name\":\"Famous Chollima deploying Python version of GolangGhost RAT - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-06-18T07:35:40+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=7011#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=7011\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=7011#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Famous Chollima deploying Python version of GolangGhost RAT\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Famous Chollima deploying Python version of GolangGhost RAT - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=7011","og_locale":"en_US","og_type":"article","og_title":"Famous Chollima deploying Python version of GolangGhost RAT - zero redgem","og_description":"Security Update News Update Information Title Famous Chollima deploying Python version of GolangGhost RAT Update ID TALOSBLOG:9AD0D911B5B851CCE8C8429BC9427AA5 Type talosblog Published 2025-06-18T10:00:44 Last Updated 2025-06-18T10:00:44 Security...","og_url":"https:\/\/zero.redgem.net\/?p=7011","og_site_name":"zero redgem","article_published_time":"2025-06-18T07:35:40+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=7011#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=7011"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Famous Chollima deploying Python version of GolangGhost RAT","datePublished":"2025-06-18T07:35:40+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=7011"},"wordCount":2546,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-0.0","exploit","news","NONE","Security","talosblog","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=7011#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=7011","url":"https:\/\/zero.redgem.net\/?p=7011","name":"Famous Chollima deploying Python version of GolangGhost RAT - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-06-18T07:35:40+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=7011#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=7011"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=7011#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Famous Chollima deploying Python version of GolangGhost RAT"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/7011","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7011"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/7011\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7011"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}