Researchers at Solar 4RAYS uncovered a long-running cyber-espionage campaign targeting at least four companies that provide services to Russian government organizations, identifying a previously unseen Golang backdoor dubbed GoblinRAT. The intrusions reportedly ran from at least October 2020 through 2023 and relied on highly stealthy, hands-on-keyboard activity on Linux systems. Investigators said the operators abused built-in Linux utilities, used unique persistence names on each host, masqueraded malicious processes as legitimate services such as Zabbix, memcached, vmtoolsd, cron, and Red Hat subscription components, and in some cases executed malware only in memory. The malware was also hidden as a malicious library loaded into atop, while command-and-control infrastructure used compromised legitimate websites and DDNS services.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Solar 4RAYS publicly reported a long-running cyber-espionage campaign affecting government-sector infrastructure and contractors, describing GoblinRAT's stealth techniques, persistence methods, and command-and-control infrastructure. The researchers said attribution remained unresolved and designated the activity cluster NGC2140.
After the suspicious activity was discovered in spring 2023, the victim organization invited Solar 4RAYS to investigate the incident. The investigation focused on stealthy Linux-based attacker activity in government-sector service providers.
In spring 2023, employees of an IT company serving mainly Russian government bodies detected a dump of user hashes from a domain controller. The hash dump had been performed with impacket-secretsdump launched from a Linux host, after which attackers cleared logs and exfiltrated data.
Solar 4RAYS traced the broader GoblinRAT activity cluster NGC2140 back to a presumed initial compromise in October 2020. Investigators also traced the malware's development history to 2020.
An early 2020 GoblinRAT server variant was identified that listened on a configured interface and required port knocking before accepting connections, showing the malware's stealth-focused design early in its development.
Using command-and-control indicators from GoblinRAT configurations, investigators identified three additional infected organizations beyond the initial victim. In total, at least four companies providing services to government organizations were found infected.
During the investigation, Solar 4RAYS identified a previously unseen Golang malware family and named it GoblinRAT. The backdoor was designed for remote access and concealment on Linux systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 57 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.