Tag: Golang Malware

APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign
News

APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign

A threat actor with ties to Pakistan has been seen launching spear-phishing operations against Indian government organizations in an attempt to spread DeskRAT, a Golang-based malware. Sekoia saw the activity in August and September of 2025, and it has been linked to Transparent Tribe (also known as APT36), a state-sponsored hacker collective that has been active since at least 2013. Additionally, it expands on a previous campaign that CYFIRMA revealed in August 2025. Phishing emails with a ZIP file attachment or, occasionally, a link to an archive stored on reputable cloud services like Google Drive are part of the attack chains. The ZIP package contains malicious desktop file embedding commands that, when run alongside the main payload, cause Mozilla Firefox to display a phony PDF ...
North Korean Hackers Deploy New Golang Malware ‘Durian’ Against Crypto Firms
News

North Korean Hackers Deploy New Golang Malware ‘Durian’ Against Crypto Firms

A previously unreported Golang-based malware known as Durian has been seen being used by the North Korean threat actor known as Kimsuky in highly focused cyberattacks against two South Korean bitcoin companies. According to Kaspersky's APT trends report for Q1 2024, "Durian boasts comprehensive backdoor functionality, enabling the execution of delivered commands, additional file downloads, and file exfiltration." The genuine software that was only available in South Korea was utilized as an infection channel in the August and November 2023 attacks. The specific method by which the product was manipulated is still unknown. It is known that the software connects to the attacker's site and retrieves a malicious payload, which initiates the infection process read more North Korean Ha...