GoBear is a Go-based backdoor associated with the North Korean threat group Kimsuky, also tracked as APT43, Emerald Sleet, and Springtail. It is part of a broader shift by the group toward Go-language tooling and is linked to the SeedpuNK malware cluster alongside AlphaSeed, BetaSeed, and Troll Stealer. GoBear has been observed as a cross-platform family with Linux-targeting variants, including malware tracked separately as Gomir, that retain closely related command structures, persistence logic, and operator tradecraft.
GoBear supports remote command execution, victim information gathering, file upload and download, TCP connection handling, self-deletion, persistence, and SOCKS5 proxy management. Linux-related variants use HTTPS-based command-and-control with custom encoding and encryption, and can establish persistence through systemd when running with elevated privileges or through cron when running without them. Reported command support includes shell execution, directory operations, sleep control, connection testing, proxy management, and bidirectional file transfer. Some Linux variants show evidence of code lineage from Windows malware through residual unsupported command handling.
GoBear has been installed through droppers masquerading as legitimate signed software installers, and the malware family has used stolen legitimate code-signing certificates as a defense-evasion measure. Related activity has included delivery through fake software installers in campaigns targeting South Korean users and environments. Tradecraft associated with the broader malware cluster indicates interest in South Korean government and public-sector ecosystems, while Kimsuky more broadly has targeted government, media, research, political, diplomatic, and foreign policy entities in South Korea and internationally.
GoBear is notable for combining conventional backdoor functionality with proxying capability that can facilitate operator access, traffic relay, and post-compromise operations. Its Linux variants underscore Kimsuky’s increasing cross-platform capability and adaptation of shared Go-based malware components across multiple backdoor families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
S2W Talon has named these malware samples BetaSeed (backdoor), AlphaSeed (backdoor), GoBear (backdoor) and Troll Stealer, respectively, based on the chronological order of their discovery.
S2W Talon has named these malware samples BetaSeed (backdoor), AlphaSeed (backdoor), GoBear (backdoor) and Troll Stealer, respectively, based on the chronological order of their discovery.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
"Aria-body has the ability to use a reverse SOCKS proxy module." / "BADHATCH can use SOCKS4 and SOCKS5 proxies..." / "Neo-reGeorg... establish a SOCKS5 proxy" / "Remcos uses the infected hosts as SOCKS5 proxies"
This campaign employed novel techniques, such as disguising malware as installation files for South Korea’s electronic document security programs in order to steal from the GPKI folder, used by government administrative and public institutions in South Korea, and exploiting the SOCKS5 protocol.
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the malware family from which Gomir is described as a Linux-targeting variant.
GoBear uses stolen legitimate code-signing certificates to evade detection.
GoBear is installed through droppers masquerading as legitimate, signed software installers.
Malware implementing SOCKS5 proxy functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.