logo

Kimsuky hackers deploy new Linux backdoor in attacks on South Korea

ID: da62b194-32a8-5ab5-97d4-4870727a089d

STIX ID: report--da62b194-32a8-5ab5-97d4-4870727a089d

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-05-16

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Symantec and S2W researchers report that North Korean APT Kimsuky used trojanized software installers in a supply-chain campaign against South Korean targets to deliver a new Linux backdoor named Gomir (a Linux variant of the GoBear backdoor) alongside Troll Stealer; Gomir implements persistence (copies to /var/log/syslogd, creates a systemd 'syslogd' service, and attempts crontab), communicates with C2 via HTTP POST, supports 17 remote operations including command execution, reverse proxying, and file exfiltration, and the researchers published indicators of compromise and analysis linking the activity to Kimsuky.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.