logo

南亚某组织的双平台后门:StealthServer

ID: c4b8c61e-6e7f-580b-9135-76bc922e493f

STIX ID: report--c4b8c61e-6e7f-580b-9135-76bc922e493f

Feed Name: QiAnXin XLab

Threat Score
85/100

Date Published: 2025-10-15

Date Updated: 2026-05-25

Author: daji

...
...

This report analyzes a cross-platform Golang backdoor family dubbed "StealthServer" (Windows and Linux variants) observed since July/August 2025, detailing loaders (.desktop and Office macro), persistence mechanisms (systemd, cron, registry, startup shortcuts, service), anti-analysis and anti-debug techniques, C2 protocols (HTTP, TCP, WebSocket) and commands (file listing, upload, execute), file-exfiltration (AES-GCM) behavior, multiple C2 domains/IPs and sample hashes, and presents a likely linkage to APT36 based on targeting, delivery patterns, development paths, and domain naming similarities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.