Springtail: New Linux Backdoor Added to Toolkit


Symantec’s Threat Hunter Team has uncovered a new Linux backdoor developed by the North Korean Springtail espionage group (aka Kimsuky) that is linked to malware used in a recent campaign against organizations in South Korea.

The backdoor (Linux.Gomir) appears to be a Linux version of the GoBear backdoor, which was used in a recent Springtail campaign that saw the attackers deliver malware via Trojanized software installation packages. Gomir is structurally almost identical to GoBear, with extensive sharing of code between malware variants.

Read more…
Source: Symantec


Sign up for our Newsletter


Related:

  • SolarWinds says it’s facing SEC ‘enforcement action’ over 2020 hack

    November 7, 2022

    The long hangover from a 2020 state-sponsored compromise still isn’t over for SolarWinds, as the software giant targeted by Russian government hackers has to pony up $26 million to shareholders and face possible enforcement action from the federal government. In a recent 8-K filing with the U.S. Securities and Exchange Commission, SolarWinds said it reached an ...

  • Greece: Report claims illegal surveillance software was used to spy on politicians, journalists and businessmen

    November 5, 2022

    Greece has been rocked by a ‘wiretapping’ scandal as a bombshell report claimed Prime Minister Kyriakos Mitsotakis ‘used state intelligence to spy on dozens of people including potential political rivals, journalists and businessmen’. Documento reported that the list of targets included former premier Antonis Samaras, current members of the cabinet and shipping magnate Vangelis Marinakis, owner ...

  • Russian spies ‘hacked Liz Truss’s phone and stole sensitive messages’

    October 29, 2022

    Liz Truss had her phone hacked by Kremlin spies while she was working as foreign secretary, according to a report. The former prime minister’s personal messages with former chancellor Kwasi Kwarteng were raided, as well as sensitive details of international negotiations, it is claimed. Security services discovered the major security breach during the summer Tory leadership election, ...

  • Cranefly: Threat Actor Uses Previously Unseen Techniques and Tools in Stealthy Campaign

    October 28, 2022

    Symantec, by Broadcom Software, has discovered a previously undocumented dropper that is being used to install a new backdoor and other tools using the novel technique of reading commands from seemingly innocuous Internet Information Services (IIS) logs. The dropper (Trojan.Geppei) is being used by an actor Symantec calls Cranefly (aka UNC3524), to install another piece of ...

  • Germany stands down cyber boss over Russian ties

    October 19, 2022

    Germany’s government has stood down the president of its Federal Office for Information Security, Arne Schönbohm, over his links to Russia. Schönbohm’s woes erupted last week when late-night chat show ZDF Magazine Royale branded him a “Cyberclown” in a Twitter thread that detailed some of the wurst moments of his career: Among the matters raised in the ...

  • Budworm: Espionage Group Returns to Targeting U.S. Organizations

    October 13, 2022

    The Budworm espionage group has mounted attacks over the past six months against a number of strategically significant targets, including the government of a Middle Eastern country, a multinational electronics manufacturer, and a U.S. state legislature. The latter attack is the first time in a number of years Symantec has seen Budworm targeting a U.S-based ...