Kimsuky's New Golang Stealer 'Troll' and 'GoBear' Backdoor Target South Korea
ID: 7b28f091-a078-5e53-9f4c-068763562687
STIX ID: report--7b28f091-a078-5e53-9f4c-068763562687
Feed Name: The Hacker News
The report details a Kimsuky-linked campaign distributing a new Go-based information stealer called Troll Stealer (and a Go backdoor, GoBear) via a signed dropper that impersonates Korean security installers; the malware harvests SSH, browser data, files, screen captures and critically exfiltrates South Korean GPKI certificates. Analysis links the tools to the Kimsuky toolset (AppleSeed/AlphaSeed similarities), notes the use of legitimate certificates (likely stolen) for signing, and ASEC/S2W findings indicate active infections (thousands) and targeted attacks against South Korean organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
