Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

AAVE Price Prediction: $80 Is the Line in the Sand — Break It or Break Down

June 17, 2026

Trident Announces Termination of Deposit Agreement, Concurrent Changes to Share Capital and Direct Listing of Ordinary Shares

June 16, 2026

Onchain Data Locks In Satoshi’s 1.1M BTC Hoard — 3 Theories on Why It Never Moves

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»North Korean Hackers Deploy Python-Based Trojan Targeting Crypto
North Korean Hackers Deploy Python-Based Trojan Targeting Crypto
Security

North Korean Hackers Deploy Python-Based Trojan Targeting Crypto

February 13, 2026No Comments3 Mins Read

A new Python-based remote access Trojan (RAT) known as PylangGhost is being deployed in cyber campaigns attributed to the North Korean-aligned group Famous Chollima.

According to research from Cisco Talos, this malware, functionally similar to the previously documented GolangGhost, is used to target individuals with experience in cryptocurrency and blockchain technologies.

Fake Job Sites Deliver PylangGhost

In recent campaigns, the attackers have been using fake job interviews to trick victims into executing malicious code. These campaigns specifically target Windows users with the new Python variant, while the Golang-based RAT continues to be used against MacOS systems.

Linux users are excluded from the current wave of activity.

The attack begins with fraudulent job postings, often impersonating well-known crypto companies like Coinbase and Uniswap.

Jobseekers are led to skill-testing websites built with the React framework, where they are asked to input personal data and complete a series of questions.

Upon completion, users are prompted to record a video by granting camera access, followed by instructions to install fake video drivers via command-line input.

Read more on social engineering tactics: 92% of Organizations Hit by Credential Compromise from Social Engineering Attacks

The malicious command triggers the download of a ZIP archive containing Python modules and a Visual Basic script. This script unzips the archive and launches the Trojan using a disguised Python interpreter named nvidia.py.

PylangGhost Capabilities and Architecture

PylangGhost is composed of six main modules, all developed in Python:

  • nvidia.py initializes the RAT, ensures persistence and establishes communication with the command-and-control (C2) server

  • config.py defines configuration settings and accepted commands

  • command.py handles C2 commands like file transfers, OS shell access and data exfiltration

  • auto.py specializes in stealing credentials and cookies from over 80 browser extensions

  • api.py manages encrypted communication with the command-and-control (C2) server using RC4 encryption

  • util.py is responsible for file compression tasks

See also  Police track $200K bitcoin robbery in Scottish first

The malware enables attackers to remotely control infected machines, upload or download files and extract sensitive data, including credentials from services like Metamask, 1Password and Phantom.

Close Parallels with Golang Version

A comparison of module structure and naming conventions between the Python and Golang versions reveals striking similarities.

This suggests a shared developer or close collaboration between authors of both variants. Although the Python version is marked as version 1.0 and the Golang version as 2.0, researchers caution against making assumptions based solely on these version numbers.

Cisco Talos has found no evidence that Cisco users were affected. Most known victims so far are located in India, and the overall impact remains limited based on open-source intelligence.

Source link

Crypto Deploy hackers Korean North PythonBased Targeting Trojan

Related Posts

Here is why Strategy's dividend-paying crypto stock is crashing to near-historic lows

June 16, 2026

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Bitcoin.com Wallet Adds FixedFloat as a Swap Provider for Flexible Crypto Swaps

June 16, 2026

India Should Mine Bitcoin Domestically to Curb Dollar Outflow, Says Crypto Educator

June 16, 2026
Top Posts

Congress Targets Crypto ATMs After Americans Lose $333M to Scams

June 15, 2026

Is Your Crypto at Risk? FBI Issues Dire Warning Over ‘Phantom Hacker’

October 3, 2023

Thorchain Loses Nearly $11M as Attackers Poison Vault Churn Process Across 4 Chains – Bitcoin News

May 15, 2026

Type above and press Enter to search. Press Esc to cancel.