logo

ExCobalt Cyber Gang Targets Russian Sectors with New GoRed Backdoor

ID: 52d5a8d1-6657-5de8-97b1-b08bc1acd400

STIX ID: report--52d5a8d1-6657-5de8-97b1-b08bc1acd400

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-06-22

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Researchers at Positive Technologies attribute active cyber espionage operations against Russian government, IT, industrial, and telecom sectors to ExCobalt (likely evolved from the Cobalt Gang). The group uses supply-chain and compromised-contractor access, a custom Golang backdoor named GoRed (with RPC C2 and credential/process/file harvesting), common post-exploitation tools and multiple Linux privilege-escalation exploits to steal data and maintain access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.