GOGITTER, GITSHELLPAD, and GOSHELL Analysis
ID: b68392e8-98cd-557e-9434-a10bd8bc16ba
STIX ID: report--b68392e8-98cd-557e-9434-a10bd8bc16ba
Feed Name: Zscaler Security Research Blog
ThreatLabz provides a technical analysis of the Gopher Strike campaign: spearphishing PDFs deliver an ISO that installs a Golang downloader (GOGITTER) which drops a persistent VBScript and an executable (GITSHELLPAD) that uses private GitHub repositories for C2. The actor deploys post-compromise tools and a GOSHELL loader that decodes and launches a stageless Cobalt Strike Beacon; the report includes C2 URLs, sample commands, GitHub repo usage, persistence mechanisms, and extracted Beacon configuration and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
