Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kimsuky used Gomir, BirdTroy, and DriveTroy to spread the infection across groupware developers and their clients.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
| Tactics | Techniques | ... | Lateral Movement | T1021 : Remote Services - nT1078 : Valid Accounts - nT1570 : Lateral Tool Transfer |
| Tactics | Techniques | ... | Initial Access | T1566 : Phishing - nT1190 : Exploit Public - Facing Application - nT1199 : Trusted Relationship |
state-sponsored threat actors and financially motivated attackers are employing a combination of supply chain attacks... After achieving the Initial Breach through phishing, social engineering, and supply chain attacks
루트 권한이 아니라면 아래 과정을 거쳐 크론탭 방식으로 지속성을 확보한다. crontab -l 로 기존 내용을 읽고, */10 * * * * <자기 경로> 항목을 붙여 cron.txt 에 기록
Configuration chiffrée en RC4 ... + Base64 URL-safe, stockée en fin de fichier
원본 삭제 ... crontab cron.txt 실행 cron.txt 삭제 후 재실행 ... delete | Bird_module_shell . Selfdelete | 자가 삭제 ... 06 | Die | 자가 삭제 + 종료
T1016 — System Network Configuration Discovery (Discovery)
T1049 — System Network Connections Discovery (Discovery)
31 | Process_Download | Transfer a file from the victim system to the C & C server ... DriveTroy ... 03 | UploadFile | Upload a file from the victim's PC to Google Drive
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used by Kimsuky to spread infections across groupware developers and their clients.
New Linux backdoor written in Go that uses Google Drive as its C2 channel, polls command files at one-second intervals, stores RC4-encrypted configuration appended to the binary, and persists via systemd using masqueraded service names.
Go-based Linux backdoor and apparent Gomir variant that abuses Google Drive for C2. It extracts embedded configuration, uses RC4 plus URL-safe Base64 for communications, polls Google Drive for commands, uploads results, supports shell execution, file transfer, persistence, self-deletion, and connection testing.
Go-based Linux backdoor assessed as a newly developed Gomir variant. It stores encrypted configuration in its own file, uses Google Drive for command polling and result upload, gathers system and external IP information, executes shell commands, transfers files, establishes persistence, and can self-delete.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.