Netskope Threat Labs

Hemigate

ATP Sandbox Adv. Heuristics

HemiGate is a backdoor used by the Earth Estries intrusion set in long term cyberespionage campaigns against government and technology organizations. The group deployed it alongside tooling such as ShadowPad and Cobalt Strike.

First seen
February 2025
Last seen
October 2026
Alert Name
Win32.Backdoor.Hemigate