Lyceum Golang HTTP Backdoor
- First seen
- 2021-07-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 14:40:20
Targeted industries: energy-and-utilities government-and-public-sector
Targeted regions: country_code:ae country_code:sa
Context
This Golang written malware is used as backdoor using the http protocol by a state sponsored threat actor (TA). This backdoor is running in a loop of three stages: - Check the connectivity - Registration of the victim - Retrieval and execution of commands This TA is using also variants .NET backdoors utilizing HTTP and DNS.
Reports & references
- research.checkpoint.com — State Sponsored Attack Groups Capitalise On Russia Ukraine War For Cyber Espionage (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lyceum Http Backdoor Golang (report)