Gopuram is a modular backdoor Trojan tracked since at least 2020 and linked in reporting to the Lazarus Group with medium-to-high confidence. It was identified as a selective second-stage payload in the 3CX supply-chain compromise, where digitally signed trojanized 3CX desktop client installers for Windows and macOS were distributed to customers. Although tainted 3CX installations were observed globally, Gopuram was reportedly deployed to fewer than ten machines, indicating highly targeted follow-on activity. Reporting states that selected victims included cryptocurrency companies, consistent with prior Lazarus targeting.
When executed, Gopuram connects to a command-and-control server and waits for commands. It supports filesystem interaction and process creation, and can launch multiple in-memory modules implemented as DLLs exporting DllGetClassObject. Observed modules included Ping, Connect, Registry, Service, Timestomp, Inject, KDU, Update, and Net. The KDU module was used to bypass driver signature enforcement and load an unsigned driver that collected information about installed AV filters and wrote it to C:\Windows\System32\catroot2\edb.chk.log.
In the 3CX-related deployments, telemetry showed a DLL named guard64.dll as Gopuram’s main module. One observed persistence mechanism used DLL hijacking via the IKEEXT service: a malicious C:\Windows\system32\wlbsctrl.dll (MD5: 9f85a07d4b4abff82ca18d990f062a84) was loaded at startup, decrypted shellcode stored at C:\Windows\System32\config\TxR<machine hardware profile GUID>.TxR.0.regtrans-ms using CryptUnprotectData, and executed the decrypted Gopuram payload. Additional sideloaded DLLs observed in related activity included ualapi.dll and ncobjapi.dll. Reported related infrastructure and indicators include wirexpro[.]com and oilycargo[.]com, and an unsigned driver with MD5 F684E10FF1FFCDD32C62E73A11382896.
Attribution reporting ties Gopuram to Lazarus based on prior co-residency with AppleJeus on a cryptocurrency company victim in Southeast Asia, overlaps in infrastructure and tooling, and its role in the 3CX intrusion. Kaspersky assessed Gopuram as the main implant and final payload in that attack chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers from Kaspersky discovered that the supply chain attack was used to deliver a backdoor tracked by the Russian firm as Gopuram.
Subsequent targeting focused on victims in the defense and cryptocurrency sectors, where attackers deployed secondary payloads such as Gopuram for credential theft and persistence.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
“Inject… mapping a shellcode to a remote process and creating a remote thread.”
“wlbsctrl.dll… decrypting and executing the shellcode… decryption… through the CryptUnprotectData API… different encryption key internally on every machine.”
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus-linked backdoor used for follow-on targeting of selected 3CX supply-chain victims; previously seen (since ~2020) on systems also infected with AppleJeus.
A modular backdoor used in highly targeted attacks against cryptocurrency organizations. It connects to a C2 server, accepts further commands, interacts with the victim file system, creates processes, and can launch at least eight in-memory DLL modules.
Modular backdoor deployed in the 3CX supply-chain campaign (selectively, mainly against crypto-related targets). Uses DLL hijacking for persistence (IKEEXT loads wlbsctrl.dll), decrypts an on-disk encrypted shellcode payload via CryptUnprotectData, then loads the main module (guard64.dll) to beacon to C2 for tasking. Supports filesystem interaction, process creation, and in-memory execution of multiple functional modules (e.g., registry/service manipulation, timestomping, injection via syscalls, and use of KDU to load an unsigned driver and enumerate AV filters).
Gopuram is a backdoor trojan used in targeted attacks, providing remote access and control to attackers. It was deployed in the 3CX supply chain attack, attributed to North Korean APT actors, and used for targeting cryptocurrency companies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.