Gokcpdoor is a Go-based backdoor associated with China-linked cyber-espionage activity targeting organizations in Japan. It has been observed in both Windows and Linux builds, with largely similar functionality across platforms, and has been linked to operations attributed to Bronze Butler, also known as Tick. The malware has been used in intrusions against enterprise environments, including campaigns exploiting Motex Lanscope Endpoint Manager as a zero-day to gain access and deploy follow-on payloads.
Earlier known variants used the KCP protocol over UDP for command-and-control communications, implemented through the kcp-go library and protected with AES-256 encryption derived via PBKDF2. These variants supported a broad remote administration feature set, including command execution, interactive shell access, file transfer, directory and process enumeration, network interface and connection inspection, port forwarding, SOCKS5 proxy management, and self-termination. The malware’s communications protocol used encoded command data and configurable listening or connection behavior depending on the variant.
Later variants observed in 2025 evolved their command-and-control design by dropping KCP support and adding multiplexed communications through a third-party library. Two operational forms have been documented: a server-type component that listens for inbound client connections, and a client-type component that initiates outbound connections to attacker-controlled infrastructure to establish a covert tunnel and backdoor access. Gokcpdoor can also establish proxy connections to support remote operations on compromised hosts.
In observed intrusion chains, Gokcpdoor has been deployed alongside other tooling such as OAED Loader, which injects payloads into legitimate executables, and ABK in earlier activity. Campaigns using Gokcpdoor have also involved DLL sideloading, remote administration, Active Directory information gathering, lateral movement, and theft of victim data. Targeting has aligned with espionage objectives affecting Japanese organizations, including sectors of strategic and economic interest.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In the 2025 campaign, CTU™ researchers confirmed that the threat actors gained initial access by exploiting CVE-2025-61932. This vulnerability allows remote attackers to execute arbitrary commands with SYSTEM privileges. ... CISA added CVE-2025-61932 to the Known Exploited Vulnerabilities Catalog on October 22.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2022 we observed the use of new APT malware by an unknown China-based APT actor across several incidents in Japan. The malware uses KCP protocol for backdoor communication and was coded in Golang on multiple platform operating systems – we named it ‘gokcpdoor’.
In 2022 we observed the use of new APT malware by an unknown China-based APT actor across several incidents in Japan. The malware uses KCP protocol for backdoor communication and was coded in Golang on multiple platform operating systems – we named it ‘gokcpdoor’.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Intrusions harnessing the critical request origin verification vulnerability in Motex Lanscope Endpoint Manager, tracked as CVE-2025-61932, as a zero-day have been launched by China-linked cyberespionage operation Bronze Butler, also known as Tick, to spread an updated Gokcpdoor malware
whoami / id Get username by executing ‘whoami’ or ‘id’ command
netstat Get network statistics about all active connections
The malware uses KCP protocol for backdoor communication... This backdoor has 20 commands and connects with C2 servers via KCP over UDP.
The malware has 20 commands, for execution, uploading and downloading files, file manipulation, port forwarding, and so on.
portfoward list: List all port forwarding settings add: Add port forwarding setting which TCP or UDP can be selected delete: Delete port forwarding setting
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based backdoor used for remote access. Observed in both a server-style implant that waits for inbound operator connections and a client-style implant that beacons outbound to the attacker to bypass network/security barriers.
Gokcpdoor is a backdoor malware used for cyberespionage, featuring multiplexed command-and-control communication and both server and client variants for persistent access and control.
Backdoor malware deployed by the Tick threat actor for cyber espionage, used to infiltrate networks via exploitation of a Lanscope vulnerability.
Backdoor used by Bronze Butler/Tick, deployed via exploitation of Motex Lanscope Endpoint Manager (CVE-2025-61932). It establishes a proxy connection to attacker C2 infrastructure; the latest version drops KCP protocol support and adds multiplexed C2 communication. Observed as both a server component (listening on ports 38000/38002) and a client component that connects to hard-coded C2 addresses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.