Gomir is a Go-based Linux remote-access trojan/backdoor associated with the North Korean threat actor Kimsuky (APT43). First reported in 2024, it has been characterized as a Linux-targeting variant of GoBear. Kimsuky deployed Gomir after compromising South Korean groupware vendors and used vendor access to target downstream customers; observed initial compromises in this activity included exploitation of an internet-exposed mail-server vulnerability and employee spearphishing.
Gomir is commonly packed with UPX and establishes persistence through a systemd service when executed with root privileges or through cron when non-root. It communicates with command-and-control infrastructure using HTTPS POST, URL-safe Base64 encoding, and custom encryption. The implant derives a victim identifier from local host attributes and supports remote shell execution, system and directory discovery, bidirectional file transfer, TCP connectivity testing, sleep and hibernation controls, and reverse-proxy functionality for reaching internal network endpoints. These functions enable persistent remote control, collection and exfiltration of host data, reconnaissance, and proxy-assisted post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kimsuky used Gomir, BirdTroy, and DriveTroy to spread the infection across groupware developers and their clients.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Vendor A (novembre 2025) : exploitation d’une vulnérabilité RCE sur un serveur de messagerie exposé sur Internet, ayant conduit à l’installation de Gomir.
state-sponsored threat actors and financially motivated attackers are employing a combination of supply chain attacks... After achieving the Initial Breach through phishing, social engineering, and supply chain attacks
Configuration chiffrée en RC4 ... + Base64 URL-safe, stockée en fin de fichier
T1016 — System Network Configuration Discovery (Discovery)
T1049 — System Network Connections Discovery (Discovery)
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated Analytic Story: Scheduled Tasks; Gomir; Data Destruction; Linux Persistence Techniques.
Used by Kimsuky to spread infections across groupware developers and their clients.
"국내 그룹웨어 대상 북한 APT 공격 분석" published by ENKI. #Kimsuky, #Phishing, #Slides, #Gomir, #HttpTroy
Linux backdoor written in Go that establishes persistence via systemd or crontab, copies itself under /var/log/rsyslogd, communicates with C2 over HTTPS POST using XOR+Base64 encoding, generates a bot ID from host attributes, and supports remote shell, file transfer, proxying, hibernation, and other backdoor commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.