GOGETTER is malware used by Sandworm Team during the 2022 Ukraine Electric Power Attack. The provided content identifies it as tunneler software deployed to establish a Yamux TLS-based command-and-control channel with external servers and to proxy C2 communications through a TLS tunnel. On Linux systems, Sandworm configured systemd to maintain GOGETTER persistence, including setting service units with WantedBy=multi-user.target so it would run when the system began accepting user logins. The actor also leveraged systemd service units to masquerade GOGETTER as legitimate or seemingly legitimate services. High-confidence details in the content tie GOGETTER specifically to Sandworm Team activity in the 2022 Ukraine Electric Power Attack. No file hashes, filenames, or network indicators beyond the Yamux TLS-based C2 channel are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During the 2022 Ukraine Electric Power Attack, Sandworm Team configured Systemd to maintain persistence of GOGETTER... deployed the GOGETTER tunneler software to establish a "Yamux" TLS-based C2 channel with an external server(s).
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware observed in the 2022 Ukraine Electric Power Attack; it was disguised via systemd service units to appear as legitimate services.
A tunneling tool used to establish a TLS-based C2 channel (Yamux) and maintained via systemd persistence; also masqueraded as legitimate services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.