logo

North Korean Espionage Group Springtail Unveils New Linux Backdoor in Escalating Cyber Campaign

ID: 2a030cc0-1c8e-5c85-b4a2-fc581f82114b

STIX ID: report--2a030cc0-1c8e-5c85-b4a2-fc581f82114b

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2024-05-20

Date Updated: 2026-04-22

Author: do son

...
...

Symantec reports that North Korean APT Springtail (Kimsuky) has deployed a new Linux backdoor called Gomir—sharing code and functionality with the Windows GoBear backdoor—that installs persistence via systemd or cron, communicates with a C2 over HTTP POST, and supports 17 commands. The discovery is part of ongoing Springtail activity including supply-chain and spear-phishing campaigns that delivered Troll Stealer and Trojanized installers targeting South Korean organizations, highlighting an active, sophisticated espionage effort.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.