logo

Kimsuky APT Deploying Linux Backdoor Gomir in South Korean Cyber Attacks

ID: 4b10fa3f-8e74-55f6-8814-233cf2b8f4c7

STIX ID: report--4b10fa3f-8e74-55f6-8814-233cf2b8f4c7

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-05-17

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Symantec reports that the North Korea-linked APT group Kimsuky (Springtail) is using a Linux backdoor named Gomir—structurally similar to its GoBear backdoor—alongside distribution of Troll Stealer via trojanized installers and fake software updaters targeting South Korean organizations, demonstrating supply-chain-style infection vectors and shared code across malware families.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.