Gomir

MITRE ATT&CK: S1198 View on attack.mitre.org

Aliases: Gomir

First seen
2021-03-15 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
linux
Related IoCs
2 (1 malicious)
Last IoC activity
2026-07-30 12:56:02
Profile updated
2026-07-07 12:51:43

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:kr country_code:us

Context

Gomir is a Linux backdoor variant of the Go-based malware GoBear, uniquely assoicated with Kimsuky operations.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Gomir (S1198). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample .incoming_30584f13c0a9d0c8 2026-07-30 2

Detection coverage

  • 174 Sigma rules

Malware & tools used

  • Encrypted Channel (attack-pattern)
  • Systemd Service (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Cron (attack-pattern)
  • Unix Shell (attack-pattern)
  • Web Protocols (attack-pattern)
  • Internal Proxy (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Local Groups (attack-pattern)
  • File Deletion (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)

Used by threat actors

Reports & references

  • Broadcom/Symantec — Springtail Kimsuky Backdoor Espionage (report)
  • security.com — Springtail Kimsuky Backdoor Espionage (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Gomir (report)
  • MITRE ATT&CK — S1198 (report)

External references