GoBear is a Go-based backdoor associated with SeedpuNK, a subgroup of the North Korean threat actor Kimsuky, also known as APT43. It belongs to a tooling cluster that includes AppleSeed, AlphaSeed, BetaSeed, and Troll Stealer. GoBear supports command execution, persistence, file upload and download, victim information gathering, TCP connection handling, self-deletion, and SOCKS5 proxy management. These capabilities provide remote control of compromised systems, data theft, and traffic forwarding through infected hosts.
GoBear is installed through droppers masquerading as legitimate, digitally signed software installers. It abuses stolen legitimate code-signing certificates to appear trustworthy and evade defenses. Samples have also used VMProtect and UPX to hinder analysis. Certificate reuse links GoBear with Troll Stealer, although their capabilities are distinct.
The family includes Windows malware and a Linux-targeting variant known as Gomir. Gomir retains the backdoor's command-execution, file-transfer, information-gathering, and proxy functionality. It communicates through HTTPS POST requests with custom encoding and encryption, and establishes persistence through systemd services when running with root privileges or scheduled cron execution otherwise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
S2W Talon has named these malware samples BetaSeed (backdoor), AlphaSeed (backdoor), GoBear (backdoor) and Troll Stealer, respectively, based on the chronological order of their discovery.
S2W Talon has named these malware samples BetaSeed (backdoor), AlphaSeed (backdoor), GoBear (backdoor) and Troll Stealer, respectively, based on the chronological order of their discovery.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
"Aria-body has the ability to use a reverse SOCKS proxy module." / "BADHATCH can use SOCKS4 and SOCKS5 proxies..." / "Neo-reGeorg... establish a SOCKS5 proxy" / "Remcos uses the infected hosts as SOCKS5 proxies"
This campaign employed novel techniques, such as disguising malware as installation files for South Korea’s electronic document security programs in order to steal from the GPKI folder, used by government administrative and public institutions in South Korea, and exploiting the SOCKS5 protocol.
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the malware family from which Gomir is described as a Linux-targeting variant.
Backdoor mentioned as the malware from which Gomir is a variant. The reference does not separately describe GoBear's capabilities or deployment.
GoBear uses stolen legitimate code-signing certificates to evade detection.
Tool/malware implementing SOCKS5 proxy functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.