Gomir

S1198

Malware.View on attack.mitre.org

About this malware

Gomir is a Linux backdoor variant of the Go-based malware GoBear, uniquely assoicated with Kimsuky operations.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1016
System Network Configuration Discovery

Gomir collects network information on infected systems such as listing interface names, MAC and IP addresses, and IPv6 addresses.

T1018
Remote System Discovery

Gomir probes arbitrary network endpoints for TCP connectivity.

T1053.003
Cron

Gomir will configure a crontab for process execution to start the backdoor on reboot if it is not initially running under group 0 privileges.

T1059.004
Unix Shell

Gomir reads command line arguments and parses them for functionality when executed from a Linux shell, and can execute arbitrary strings passed to it as shell commands.

T1069.001
Local Groups

Gomir checks the effective group ID of its process when initially executed to determine if it is in group 0, denoting superuser privileges in Linux environments.

T1070.004
File Deletion

Gomir deletes its original executable and terminates its original process after creating a systemd service.

T1071.001
Web Protocols

Gomir periodically communicates to its command and control infrastructure through HTTP POST requests.

T1082
System Information Discovery

Gomir collects information on infected systems such as hostname, username, CPU, and RAM information.

T1083
File and Directory Discovery

Gomir collects information about directory and file structures, including total number of subdirectories, total number of files, and total size of files on infected systems.

T1090.001
Internal Proxy

Gomir can start a reverse proxy to initiate connections to arbitrary endpoints in victim networks.

T1132.001
Standard Encoding

Gomir uses Base64-encoded content in HTTP communications to command and control infrastructure.

T1543.002
Systemd Service

Gomir creates a systemd service named `syslogd` for persistence.

T1573
Encrypted Channel

Gomir uses a custom encryption algorithm for content sent to command and control infrastructure.

T1573.002
Asymmetric Cryptography

Gomir uses reverse proxy functionality that employs SSL to encrypt communications.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Symantec Troll Stealer 2024 Open source
    Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.