North Korean Espionage Group Springtail Unveils New Linux Backdoor in Escalating Cyber Campaign
ID: 2a030cc0-1c8e-5c85-b4a2-fc581f82114b
STIX ID: report--2a030cc0-1c8e-5c85-b4a2-fc581f82114b
Feed Name: securityonline.info
Symantec reports that North Korean APT Springtail (Kimsuky) has deployed a new Linux backdoor called Gomir—sharing code and functionality with the Windows GoBear backdoor—that installs persistence via systemd or cron, communicates with a C2 over HTTP POST, and supports 17 commands. The discovery is part of ongoing Springtail activity including supply-chain and spear-phishing campaigns that delivered Troll Stealer and Trojanized installers targeting South Korean organizations, highlighting an active, sophisticated espionage effort.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
