Netskope Threat Labs

Fuerboos

ATP Sandbox Adv. Heuristics

Fuerboos (a.k.a. Goodor) is a backdoor written in Go and associated with the Dragonfly intrusion set, a group known for targeting energy and industrial organizations. The backdoor gives operators remote control of infected systems, including command execution and payload downloads, and its Go implementation produces large, cross platform binaries that resist casual analysis. Researchers have tied it to campaigns that probe industrial networks and maintain long term access to high value environments.

First seen
February 2022
Last seen
March 2026
Alert Name
ByteCode-MSIL.Trojan.Fuerboos
Unknown.Trojan.Fuerboos
Win32.Trojan.Fuerboos
Win64.Trojan.Fuerboos