Netskope Threat Labs

Gomir

ATP Sandbox Adv. Heuristics

Gomir is a Linux backdoor variant of the Go based GoBear malware, uniquely associated with the Kimsuky threat actor's operations.

First seen
May 2024
Last seen
September 2026

14 techniques across 5 tactics.

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1018Remote System Discovery
  • T1069Permission Groups Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0011 Command and Control

Alert Name
Linux.Backdoor.Gomir