Kimsuky组织最新Linux.Gomir后门功能&通信模型剖析及攻击场景复现

2024-05-27 Aliyun Analysis of the latest Kimsuky Linux.Gomir backdoor functions, communication model, and attack-scenario reproduction

https://xz.aliyun.com/t/14673

Thumbnail for Kimsuky组织最新Linux.Gomir后门功能&通信模型剖析及攻击场景复现

The report analyzes Kimsuky use of the Linux.Gomir backdoor after Symantec reporting and focuses on Golang reverse engineering, persistence, debugging, and command-and-control behavior. It describes installation as a systemd service under syslogd, cron-based persistence for non-root execution, related Windows variants, and infrastructure links that help defenders track Kimsuky backdoor tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 216.189.159.34 2024-05-16 2024-06-27

Related Actors

Related Reports

« Back