logo

StealthServer: A Dual-Platform Backdoor from a South Asian APT Group

ID: ab7ee057-5b15-5140-bc3c-16e06b917f82

STIX ID: report--ab7ee057-5b15-5140-bc3c-16e06b917f82

Feed Name: QiAnXin XLab

Threat Score
78/100

Date Published: 2025-10-15

Date Updated: 2026-05-25

Author: daji

...
...

This report details analysis of a Go‑based backdoor dubbed “StealthServer” observed since July targeting Windows and Linux in the South Asian region. Attackers deliver the payload via malicious Office macros and .desktop PDF shortcuts that display decoy documents while installing the backdoor; capabilities include file exfiltration, remote command execution, persistence (registry/startup/systemd/cron), anti‑analysis techniques, and varied transports (TCP, HTTP, WebSocket). The report lists C2 domains and IPs, file hashes, development build paths, and notes overlap in TTPs and infrastructure with the APT36 actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.