ExCobalt Cyber Gang Targets Russian Sectors with New GoRed Backdoor
ID: 52d5a8d1-6657-5de8-97b1-b08bc1acd400
STIX ID: report--52d5a8d1-6657-5de8-97b1-b08bc1acd400
Feed Name: The Hacker News
Threat Score
Researchers at Positive Technologies attribute active cyber espionage operations against Russian government, IT, industrial, and telecom sectors to ExCobalt (likely evolved from the Cobalt Gang). The group uses supply-chain and compromised-contractor access, a custom Golang backdoor named GoRed (with RPC C2 and credential/process/file harvesting), common post-exploitation tools and multiple Linux privilege-escalation exploits to steal data and maintain access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
