GoBear

S1197

Malware.View on attack.mitre.org

About this malware

GoBear is a Go-based backdoor that abuses legitimate, stolen certificates for defense evasion purposes. GoBear is exclusively linked to Kimsuky operations.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

GoBear is installed through droppers masquerading as legitimate, signed software installers.

T1090
Proxy

GoBear implements SOCKS5 proxy functionality.

T1553.002
Code Signing

GoBear uses stolen legitimate code signing certificates for defense evasion.

Groups that use it1

Campaigns0

None recorded.

References2

  1. S2W Troll Stealer 2024 Open source
    Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.
  2. Symantec Troll Stealer 2024 Open source
    Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.