In November 20233, a Go-based backdoor known as GoGra—which had not yet been documented—was used to target an unidentified South Asian media company.
According to a research published with The Hacker News by Symantec, a division of Broadcom, GoGra is developed in Go and communicates with a command-and-control (C&C) server housed on Microsoft mail services via the Microsoft Graph API.
Currently, it’s unclear how target environments will receive it. On the other hand, GoGra is set up to read messages from the Outlook login “FNU LNU” that begin with the word “Input.”
After the contents of the message are decrypted using a key and the AES-256 method in Cipher Block Chaining (CBC) mode, cmd.exe is used to carry out the commands read more about New Go based Backdoor GoGra Targets South Asian Media Organization.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
