Springtail: New Linux Backdoor Added to Toolkit

2024-05-16 Symantec

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/springtail-kimsuky-backdoor-espionage

Thumbnail for Springtail: New Linux Backdoor Added to Toolkit

Symantec attributes a new Linux backdoor, Linux.Gomir, to Springtail, also known as Kimsuky, in activity linked to recent campaigns against South Korean organizations. Gomir is a Linux counterpart to the GoBear backdoor and shares extensive code with it, extending Springtail’s Go-based tooling across platforms. The campaign used trojanized Korean software installers, including TrustPKI, NX_PRNMAN, and Wizvera VeraPort packages, to deliver Troll Stealer and related backdoors. Gomir can install itself as a systemd service named syslogd when run with privileges, while the broader toolset supports information theft, screenshots, browser-data collection, and persistence against South Korean government and public-sector targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8e45daace21f135b54c515dbd5cf6e0… 2024-05-16 2024-12-13
HASH 7bd723b5e4f7b3c645ac04e763dfc91… 2024-05-16 2024-12-13
HASH 47d084e54d15d5d313f09f5b5fcdea0… 2024-05-16 2024-12-13
HASH 30584f13c0a9d0c86562c803de35043… 2024-05-16 2024-11-20
IPv4 216.189.159.34 2024-05-16 2024-06-27
HASH ff945b3565f63cef7bb214a93c62368… 2024-05-16 2024-05-16
HASH d05c50067bd88dae4389e96d7e88b58… 2024-05-16 2024-05-16
HASH d7f3ecd8939ae8b170b641448ff12ad… 2024-05-16 2024-05-16
HASH a98c017d1b9a18195411d22b44dbe65… 2024-05-16 2024-05-16
HASH 831f27eb18caf672d43a5a80590df13… 2024-05-16 2024-05-16
HASH ecab00f86a6c3adb5f4d5b16da56e16… 2024-05-16 2024-05-16
HASH 8898b6b3e2b7551edcceffbef2557b9… 2024-05-16 2024-05-16
HASH 5068ead78c226893df638a188fbe722… 2024-05-16 2024-05-16
HASH 8a80b6bd452547650b3e61b2cc301d5… 2024-05-16 2024-05-16
HASH cc7a123d08a3558370a32427c8a5d15… 2024-05-16 2024-05-16
HASH 36ea1b317b46c55ed01dd860131a7f6… 2024-05-16 2024-05-16
HASH 6c2a8e2bbe4ebf1fb6967a342112819… 2024-05-16 2024-05-16
HASH 380ec7396cc67cf1134f8e8cda906b6… 2024-05-16 2024-05-16
HASH bc4c1c869a03045e0b594a258ec3801… 2024-02-07 2024-05-16

Related Actors

Related Reports

« Back