Trend Micro researchers reported that the Chinese-speaking threat actor Earth Lusca used a previously undocumented Golang backdoor called KTLVdoor in a broad intrusion campaign targeting both Windows and Linux systems. The malware was designed for stealth, often disguising itself as legitimate system utilities while giving operators extensive remote access, including command execution, file management, proxying, and port scanning. Investigators identified at least one victim, a trading company in China.
KTLVdoor uses a custom TLV-like configuration format with encrypted values and protects command-and-control traffic with GZIP and AES-GCM, complicating analysis and detection. Researchers tied the activity to more than 50 command-and-control servers hosted on Alibaba infrastructure in China, but said attribution across the full server set remains uncertain because some tooling or infrastructure may be shared with other Chinese-speaking threat actors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Trend Micro publicly disclosed KTLVdoor and described its obfuscation, custom TLV-like configuration format, encrypted communications, and broad remote access capabilities including command execution, file operations, proxying, and port scanning.
Researchers found more than 50 command-and-control servers communicating with KTLVdoor variants, all hosted on Alibaba infrastructure in China. They also identified at least one target of the operation: a trading company based in China.
While monitoring the Chinese-speaking threat actor Earth Lusca, researchers identified a previously unreported Golang backdoor named KTLVdoor with Windows and Linux variants. They tied some samples to Earth Lusca with high confidence, while noting the broader infrastructure may also be shared with other Chinese-speaking actors.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.