StealthServer: A Dual-Platform Backdoor from a South Asian APT Group
ID: ab7ee057-5b15-5140-bc3c-16e06b917f82
STIX ID: report--ab7ee057-5b15-5140-bc3c-16e06b917f82
Feed Name: QiAnXin XLab
This report details analysis of a Go‑based backdoor dubbed “StealthServer” observed since July targeting Windows and Linux in the South Asian region. Attackers deliver the payload via malicious Office macros and .desktop PDF shortcuts that display decoy documents while installing the backdoor; capabilities include file exfiltration, remote command execution, persistence (registry/startup/systemd/cron), anti‑analysis techniques, and varied transports (TCP, HTTP, WebSocket). The report lists C2 domains and IPs, file hashes, development build paths, and notes overlap in TTPs and infrastructure with the APT36 actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
