Researchers documented multiple malware families implemented in Go, including a newly analyzed information stealer and a Sofacy-linked Zebrocy variant. The stealer was designed to harvest data from infected systems, while the Go-based Zebrocy samples preserved the espionage-focused behavior seen in earlier versions, including host reconnaissance, screenshot capture, and command-and-control beaconing over HTTP or HTTPS. The shift to Go mirrors a broader pattern of attackers reworking established tooling in less common languages to complicate detection and analysis.
Unit 42 reported that Sofacy delivered the Go Zebrocy malware through spear-phishing chains using a malicious .lnk file disguised as a Word document and a separate Word document that retrieved a remote template with a macro. Although one LNK-based chain failed because of an incorrect hardcoded filename, the campaign exposed intended payload delivery and infrastructure. In the later chain, the macro dropped a UPX-packed Go downloader, established persistence with a Run registry key, and fetched an additional payload, while analysts also noted overlaps with earlier Zebrocy activity, including reused C2 patterns and beacon strings.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On December 5, 2018, Bitly statistics observed for the Dear Joohn campaign link showed it had been created on December 3 and had received 75 visits, mostly from Turkey. This provided evidence that the delivery infrastructure was active and attracting targets.
A second delivery chain tied to the "Dear Joohn" campaign used a Word document and shortened Bitly link that were both created on December 3, 2018. The document fetched a remote template containing a macro that ultimately dropped and ran a Go Zebrocy downloader.
On October 11, 2018, Sofacy used a spear-phishing email with an LNK file masquerading as a Word document to deliver a new Go-based Zebrocy variant. The chain was intended to drop a decoy document and a Go Zebrocy executable, but execution failed because the embedded PowerShell referenced the wrong LNK filename.
Unit 42 reported that Sofacy had introduced a new Zebrocy variant written in Go and documented two observed delivery chains using it. The analysis linked the malware to prior Zebrocy activity through shared infrastructure and overlapping beacon characteristics.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.