Kimsuky组织最新Linux.Gomir后门功能&通信模型剖析及攻击场景复现
2024-05-27 • Aliyun • Analysis of the latest Kimsuky Linux.Gomir backdoor functions, communication model, and attack-scenario reproduction •
The report analyzes Kimsuky use of the Linux.Gomir backdoor after Symantec reporting and focuses on Golang reverse engineering, persistence, debugging, and command-and-control behavior. It describes installation as a systemd service under syslogd, cron-based persistence for non-root execution, related Windows variants, and infrastructure links that help defenders track Kimsuky backdoor tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 216.189.159.34 | 2024-05-16 | 2024-06-27 |
Related Actors
Related Reports
Shares tags: Kimsuky, Gomir • Shares 1 IOC
Shares tag: Gomir • Shares 1 IOC • Published within a month
Shares tag: Kimsuky • Same author: Aliyun • Published within a month
Shares tag: Kimsuky • Same author: Aliyun • Published within a month
2024-06-26 •
60% Match
#Kimsuky
Shares tag: Kimsuky • Published within a month
Shares tag: Kimsuky • Published within a month