SADBRIDGE Loader Unveils GOSAR Backdoor in Cyber Attacks
ID: b643897c-91a0-56c2-91f9-9d7043a066b5
STIX ID: report--b643897c-91a0-56c2-91f9-9d7043a066b5
Feed Name: securityonline.info
Threat Score
### Executive summary Elastic Security Labs identified GOSAR, a Golang rewrite of the QUASAR RAT deployed via a SADBRIDGE loader in campaigns attributed to REF3864; attackers use malicious MSI installers and DLL side‑loading to achieve persistence, privilege escalation, and cross‑platform backdoor operations including keylogging, HVNC, and C2 communications while employing API patching and encryption to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
