#GoBear
Malware/Tool
2024-05-16 • Springtail: New Linux Backdoor Added to Toolkit
GoBear is a backdoor used by the North Korean Springtail espionage group, also known as Kimsuky, in a campaign against organizations in South Korea. It was delivered through trojanized software installation packages. The Linux backdoor Gomir is described as a Linux version of GoBear and is structurally almost identical to it, with extensive code sharing between the two variants. MITRE ATT&CK S1197.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days