Gopuram

First seen
2016-09-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 15:03:57

Targeted industries: financial-services

Targeted regions: country_code:in

Context

Gopuram is a sophisticated backdoor malware primarily targeting financial institutions in South Asia. It is known for its stealthy operation and advanced capabilities, making it a tool of choice for persistent threat actors.

Detection coverage

  • 5 YARA rules

Detection rules

  • SEKOIA_Apt_Lazarus_Gopuram_Backdoor (yara-rule)
  • SIGNATURE_BASE_MAL_Gopuram_Apr23 (yara-rule)
  • SIGNATURE_BASE_MAL_Shellcode_Loader_Apr23 (yara-rule)
  • SIGNATURE_BASE_APT_MAL_Gopuram_Backdoor_Apr23 (yara-rule)
  • MALPEDIA_Win_Gopuram_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Gopuram (report)
  • twitter.com — 1642886340105601029 (report)
  • Kaspersky — 109344 (report)

External references