Lyceum Golang HTTP Backdoor

First seen
2021-07-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 14:40:20

Targeted industries: energy-and-utilities government-and-public-sector

Targeted regions: country_code:ae country_code:sa

Context

This Golang written malware is used as backdoor using the http protocol by a state sponsored threat actor (TA). This backdoor is running in a loop of three stages: - Check the connectivity - Registration of the victim - Retrieval and execution of commands This TA is using also variants .NET backdoors utilizing HTTP and DNS.

Reports & references

  • research.checkpoint.com — State Sponsored Attack Groups Capitalise On Russia Ukraine War For Cyber Espionage (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lyceum Http Backdoor Golang (report)

External references