#GoBear

Malware/Tool

2024-05-16 • Springtail: New Linux Backdoor Added to Toolkit

GoBear is a backdoor used by the North Korean Springtail espionage group, also known as Kimsuky, in a campaign against organizations in South Korea. It was delivered through trojanized software installation packages. The Linux backdoor Gomir is described as a Linux version of GoBear and is structurally almost identical to it, with extensive code sharing between the two variants. MITRE ATT&CK S1197.

Tagged Reports

« Back