#Gomir

Malware/Tool

2024-05-16 • Springtail: New Linux Backdoor Added to Toolkit

Gomir is a Go-based Linux remote-access backdoor used by Kimsuky and derived from the Windows GoBear backdoor. It has been deployed against South Korean groupware vendors and servers following exploitation of an internet-facing mail server or suspected spear-phishing. Gomir executes shell commands, collects system information, transfers files, tests TCP connections, performs reverse port forwarding, sleeps on a schedule, and can terminate itself. Root installations persist as a syslogd systemd service, while non-root installations use cron. Reported C2 uses HTTP or HTTPS, including POST traffic with custom encryption and Base64 encoding. MITRE ATT&CK S1198.

Tagged Reports

« Back