GoBear

GoBear is a Go-based backdoor that abuses legitimate, stolen certificates for defense evasion purposes. GoBear is exclusively linked to Kimsuky operations.[1][2]

ID: S1197
Type: MALWARE
Platforms: Windows
Version: 1.0
Created: 17 January 2025
Last Modified: 17 January 2025

Techniques Used

Domain ID Name Use
Enterprise T1036 .005 Masquerading: Match Legitimate Resource Name or Location

GoBear is installed through droppers masquerading as legitimate, signed software installers.[2]

Enterprise T1090 Proxy

GoBear implements SOCKS5 proxy functionality.[1]

Enterprise T1553 .002 Subvert Trust Controls: Code Signing

GoBear uses stolen legitimate code signing certificates for defense evasion.[1][2]

Groups That Use This Software

ID Name References
G0094 Kimsuky

GoBear is exclusively linked to Kimsuky operations.[1][2]

References