RnD Research Lab

Cyber Security => IT News => Topic started by: ixsky on

Title: Kimsuky APT Deploying Linux Backdoor Gomir in South Korean Cyber Attacks
Post by: ixsky on
Kimsuky APT Deploying Linux Backdoor Gomir in South Korean Cyber Attacks

The Kimsuky (aka Springtail) advanced persistent threat (APT) group, which is linked to North Korea's Reconnaissance General Bureau (RGB), has been observed deploying a Linux version of its GoBear backdoor as part of a campaign targeting South Korean organizations.
The backdoor, codenamed Gomir, is "structurally almost identical to GoBear, with extensive sharing of code between

Source: Kimsuky APT Deploying Linux Backdoor Gomir in South Korean Cyber Attacks (https://thehackernews.com/2024/05/kimsuky-apt-deploying-linux-backdoor.html)