Symantec’s Threat Hunter Team has uncovered a new Linux backdoor developed by the North Korean Springtail espionage group (aka Kimsuky) that is linked to malware used in a recent campaign against organizations in South Korea.
The backdoor (Linux.Gomir) appears to be a Linux version of the GoBear backdoor, which was used in a recent Springtail campaign that saw the attackers deliver malware via Trojanized software installation packages. Gomir is structurally almost identical to GoBear, with extensive sharing of code between malware variants.
Read more…
Source: Symantec
Related:
- Storm-0978 attacks reveal financial and espionage motives
July 11, 2023
Microsoft has identified a phishing campaign conducted by the threat actor tracked as Storm-0978 targeting defense and government entities in Europe and North America. The campaign involved the abuse of CVE-2023-36884, which included a remote code execution vulnerability exploited before disclosure to Microsoft via Word documents, using lures related to the Ukrainian World Congress. Read more… Source: Microsoft
- France set to allow police to spy on suspects through remote phone access
July 6, 2023
Part of a wider justice reform bill, the spying provision has been attacked by the left and rights defenders as an authoritarian snoopers’ charter, though Justice Minister Eric Dupond-Moretti insists it would affect only “dozens of cases a year”. Covering laptops, cars and other connected objects as well as phones, the measure would allow geolocation of ...
- The growth of commercial spyware based intelligence providers without legal or ethical supervision
July 6, 2023
Attackers have long used commercial products developed by legitimate companies to compromise targeted devices. These products are known as commercial spyware. Commercial spyware operations mainly target mobile platforms with zero- or one-click zero-day exploits to deliver spyware. This threat initially came to light with the leaks of HackingTeam back in 2015, but gained new notoriety with public reporting ...
- Chinese threat actors targeting Europe in SmugX campaign
July 3, 2023
In the last couple of months, Check Point Research (CPR) has been tracking the activity of a Chinese threat actor targeting Foreign Affairs ministries and embassies in Europe. Combined with other Chinese activity previously reported by Check Point Research, this represents a larger trend within the Chinese ecosystem, pointing to a shift to targeting European entities, ...
- Turkish intelligence uncovers ‘ghost’ Mossad network
July 3, 2023
After monthslong surveillance, Türkiye’s National Intelligence Organization (MIT) has exposed a “ghost” cell of 56 operatives spying on non-Turkish nationals in the country on behalf of the Israeli intelligence agency Mossad. Documents from MIT revealed that the spies were gathering biographical intelligence on foreign nationals through an online routing method, tracking vehicle movements via GPS, hacking ...
- EU set to approve the use of spyware to uncover confidential journalist sources
June 23, 2023
The European Union is set to approve new laws that would let governments spy on journalists in the name of national security. The legislation would expand legal ‘loopholes’ that let governments install spyware on journalist’s phones and computers, including British reporters working in the EU, press freedom campaigners warned. The draft legislation, that has now been ...

