Gomir
MITRE ATT&CK: S1198 View on attack.mitre.org
Aliases: Gomir
- First seen
- 2021-03-15 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- linux
- Related IoCs
- 2 (1 malicious)
- Last IoC activity
- 2026-07-30 12:56:02
- Profile updated
- 2026-07-07 12:51:43
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:kr country_code:us
Context
Gomir is a Linux backdoor variant of the Go-based malware GoBear, uniquely assoicated with Kimsuky operations.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Gomir (S1198). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | .incoming_30584f13c0a9d0c8 | 2026-07-30 | 2 |
Detection coverage
- 174 Sigma rules
Malware & tools used
- Encrypted Channel (attack-pattern)
- Systemd Service (attack-pattern)
- Remote System Discovery (attack-pattern)
- Standard Encoding (attack-pattern)
- Cron (attack-pattern)
- Unix Shell (attack-pattern)
- Web Protocols (attack-pattern)
- Internal Proxy (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Local Groups (attack-pattern)
- File Deletion (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
Used by threat actors
- Kimsuky (threat-actor)
Reports & references
- Broadcom/Symantec — Springtail Kimsuky Backdoor Espionage (report)
- security.com — Springtail Kimsuky Backdoor Espionage (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Gomir (report)
- MITRE ATT&CK — S1198 (report)