南亚某组织的双平台后门:StealthServer
ID: c4b8c61e-6e7f-580b-9135-76bc922e493f
STIX ID: report--c4b8c61e-6e7f-580b-9135-76bc922e493f
Feed Name: QiAnXin XLab
This report analyzes a cross-platform Golang backdoor family dubbed "StealthServer" (Windows and Linux variants) observed since July/August 2025, detailing loaders (.desktop and Office macro), persistence mechanisms (systemd, cron, registry, startup shortcuts, service), anti-analysis and anti-debug techniques, C2 protocols (HTTP, TCP, WebSocket) and commands (file listing, upload, execute), file-exfiltration (AES-GCM) behavior, multiple C2 domains/IPs and sample hashes, and presents a likely linkage to APT36 based on targeting, delivery patterns, development paths, and domain naming similarities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
