Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kimsuky used Gomir, BirdTroy, and DriveTroy to spread the infection across groupware developers and their clients.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
| Tactics | Techniques | ... | Lateral Movement | T1021 : Remote Services - nT1078 : Valid Accounts - nT1570 : Lateral Tool Transfer |
| Tactics | Techniques | ... | Initial Access | T1566 : Phishing - nT1190 : Exploit Public - Facing Application - nT1199 : Trusted Relationship |
state-sponsored threat actors and financially motivated attackers are employing a combination of supply chain attacks... After achieving the Initial Breach through phishing, social engineering, and supply chain attacks
Configuration chiffrée en RC4 ... + Base64 URL-safe, stockée en fin de fichier
/var/log/rsyslogd 로 자기 복사 ... /etc/systemd/system/rsyslogd.service 유닛 작성 ... DriveTroy ... 서비스명 | syslogd , logd , cachelogd , cachemond , monlogd 중 랜덤 선택
원본 삭제 ... crontab cron.txt 실행 cron.txt 삭제 후 재실행 ... delete | Bird_module_shell . Selfdelete | 자가 삭제 ... 06 | Die | 자가 삭제 + 종료
31 | Process_Download | Transfer a file from the victim system to the C & C server ... DriveTroy ... 03 | UploadFile | Upload a file from the victim's PC to Google Drive
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used by Kimsuky to spread infections across groupware developers and their clients.
New Linux RAT written in Go that shares command handling and persistence logic with Gomir and HttpTroy, uses Base64-encoded custom packets with MD5 checksum, and supports HTTP/3 (QUIC) for C2 to evade TCP-focused network appliances.
Previously unpublished Go-based Linux RAT/backdoor that combines traits of Gomir and HttpTroy. It supports persistence identical to Gomir, HTTP or HTTP/3 C2 communications, shell execution, self-deletion, screenshot capture, and bidirectional file transfer.
Previously undocumented Go-based Linux RAT/backdoor that appears to be a Gomir variant. It supports persistence, duplicate-execution prevention, HTTP or HTTP/3 C2 transport, shell command execution, screenshot capture, self-deletion, sleep control, and bidirectional file transfer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.