CosmicDoor is a remote-control backdoor malware family used by the North Korea-linked BlueNoroff threat actor, also tracked as Sapphire Sleet, APT38, Stardust Chollima, TA444, Alluring Pisces, CageyChameleon, CryptoCore, Genie Spider, and Nickel Gladstone, in the broader SnatchCrypto operation. It has been observed in the GhostCall and GhostHire campaigns targeting blockchain developers, Web3 companies, executives, managers, and venture capital personnel, with victims reported across multiple countries including Japan, Italy, France, Singapore, Turkey, Spain, Sweden, India, Hong Kong, and Australia.
On macOS, CosmicDoor is described as a Nim-based backdoor injected using a C++ injector/loader called GillyInjector (also referred to as InjectWithDyld) into a benign Mach-O application at runtime. It communicates with command-and-control infrastructure over WSS and provides remote command execution capability. Reporting also states that the macOS variant downloads a bash-based stealer suite named SilentSiphon. CosmicDoor appears in multi-stage infection chains delivered through fake Zoom or Microsoft Teams meeting lures in the GhostCall campaign, where victims are socially engineered via Telegram and phishing pages into downloading malicious AppleScript-based updates or SDK files that lead to DownTroy and subsequent payload deployment.
On Windows, CosmicDoor has been reported as a Go-based variant used in the GhostHire campaign. It communicates with a WSS C2, with one report citing the hardcoded endpoint wss://second.systemupdate[.]cloud/client, and supports command execution plus PE injection via a "shoot" or "shoote" syntax. GhostHire delivered CosmicDoor through fake recruiter workflows, Telegram bots, GitHub repositories, and ZIP-based coding assessments containing malicious dependencies such as the Go package uniroute. Content also notes Kaspersky’s assessment that CosmicDoor may have first been developed as a Go version for Windows and later expanded into Rust, Python, and Nim variants.
CosmicDoor is consistently characterized as part of BlueNoroff’s modular, cross-platform malware ecosystem alongside DownTroy, RooTroy, RealTimeTroy, SilentSiphon, ZoomClutch, TeamsClutch, SneakMain, and SysPhon.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The ultimately injected payload is identified as CosmicDoor.macOS, written in Nim. The main feature of CosmicDoor is that it communicates with the C2 server using the WSS protocol, and it provides remote control functionality such as receiving and executing commands.
The injected payload is a backdoor written in Nim named CosmicDoor that can communicate with an external server to receive and execute commands. ... It also downloads a bash script stealer suite named SilentSiphon.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware samples were found written in multiple programming languages, including Go, Rust, Nim, and AppleScript, reflecting an added technical layer in the group’s operations.
GillyInjector employs a technique known as Task Injection... designed to run a benign Mach-O app and inject a malicious payload into it at runtime... DownTroy.Windows would retrieve a base64-encoded binary blob... and inject it into the cmd.exe process... RealTimeTroy... injects the payload received from the C2.
The campaign also deploys exfiltration routines to extract sensitive project data back to BlueNoroff’s servers, often obfuscated with custom encryption and encoded in hexadecimal to avoid detection.
GillyInjector employs a technique known as Task Injection... designed to run a benign Mach-O app and inject a malicious payload into it at runtime... DownTroy.Windows would retrieve a base64-encoded binary blob... and inject it into the cmd.exe process... RealTimeTroy... injects the payload received from the C2.
all three DownTroy strains collect comprehensive system information including OS details, domain name, host name, username, proxy settings, and VM detection alongside process lists... SysPhon... conduct system reconnaissance by executing a series of commands.
The main feature of CosmicDoor is that it communicates with the C2 server using the WSS protocol... RealTimeTroy is a straightforward backdoor written in the Go programming language that communicates with a C2 server using the WSS protocol.
DownTroy would download ZIP files that contain various individual infection chains from the actor’s centralized file hosting server... When both the url and auth fields are present, RooTroy connects to the URL... to retrieve additional files.
The main feature of CosmicDoor is that it communicates with the C2 server using the WSS protocol, and it provides remote control functionality such as receiving and executing commands... SneakMain... receives additional AppleScript commands and uses the osascript -e command to execute them.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor payload deployed on both macOS and Windows (including a Go-based Windows variant) as part of BlueNoroff’s SnatchCrypto operation.
CosmicDoor is an implant used in BlueNoroff's GhostCall campaign, performing keylogging and potentially other surveillance functions as part of a multi-stage attack.
Remote-control malware (RAT-like capability) used by BlueNoroff, including a Windows variant noted in GhostHire, to enable remote access/control of compromised hosts.
Backdoor (noted here as a Nim variant) delivered via loader/injection tooling; communicates with an external server for command execution and is associated with downloading the SilentSiphon stealer suite. The actor is described as having developed multiple language variants (Go/Windows, then Rust/Python/Nim).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.