Gopuram
- First seen
- 2016-09-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 15:03:57
Targeted industries: financial-services
Targeted regions: country_code:in
Context
Gopuram is a sophisticated backdoor malware primarily targeting financial institutions in South Asia. It is known for its stealthy operation and advanced capabilities, making it a tool of choice for persistent threat actors.
Detection coverage
- 5 YARA rules
Detection rules
- SEKOIA_Apt_Lazarus_Gopuram_Backdoor (yara-rule)
- SIGNATURE_BASE_MAL_Gopuram_Apr23 (yara-rule)
- SIGNATURE_BASE_MAL_Shellcode_Loader_Apr23 (yara-rule)
- SIGNATURE_BASE_APT_MAL_Gopuram_Backdoor_Apr23 (yara-rule)
- MALPEDIA_Win_Gopuram_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Gopuram (report)
- twitter.com — 1642886340105601029 (report)
- Kaspersky — 109344 (report)