logo

SADBRIDGE Loader Unveils GOSAR Backdoor in Cyber Attacks

ID: b643897c-91a0-56c2-91f9-9d7043a066b5

STIX ID: report--b643897c-91a0-56c2-91f9-9d7043a066b5

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-12-17

Date Updated: 2026-04-22

Author: do son

...
...

### Executive summary Elastic Security Labs identified GOSAR, a Golang rewrite of the QUASAR RAT deployed via a SADBRIDGE loader in campaigns attributed to REF3864; attackers use malicious MSI installers and DLL side‑loading to achieve persistence, privilege escalation, and cross‑platform backdoor operations including keylogging, HVNC, and C2 communications while employing API patching and encryption to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.