New Golang malware capable of cross-platform backdoor attacks spotted in the wild

Magnifying glass enlarging the word 'malware' in computer machine code
(Image credit: Shutterstock)

Cybersecurity researchers from Trend Micro have recently spotted a never-before-seen backdoor malware being used to target a Chinese trading company.

The malware is called KTLVdoor, and since it’s written Golang, it can be used against both Windows and Linux-powered endpoints. It is designed to tamper with files, run code, and more: "KTLVdoor is a highly obfuscated malware that masquerades as different system utilities, allowing attackers to carry out a variety of tasks including file manipulation, command execution, and remote port scanning," Trend Micro researchers said in a security advisory published earlier this week.

The researchers also said that the tool masquerades as sshd, Java, SQLite, bash, edr-agent, and more.

Earth Lusca Golang malware

It was built by a Chinese threat actor called Earth Lusca. Apparently, the group distributes the malware either as a .DLL file, or as a .SO (shared object). However, the researchers are still pretty much in the dark when it comes to distribution: "This new tool is used by Earth Lusca, but it might also be shared with other Chinese-speaking threat actors," the researchers said. "Seeing that all C&C servers were on IP addresses from China-based provider Alibaba, we wonder if the whole appearance of this new malware and the C&C server could not be some early stage of testing new tooling."

Speaking of C2 servers, Trend Micro found more than 50 of them, all hosted on Alibaba. This led them to speculate that multiple groups could be sharing the same infrastructure.

Earth Lusca is a sophisticated cyber threat actor group, believed to be linked to advanced persistent threats (APTs) with a focus on espionage and intelligence gathering. The group, whose first reported activity dates back to 2021, is known for targeting a wide range of sectors, including government agencies, healthcare, telecommunications, and education, primarily in Southeast Asia.

Via The Hacker News

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Telegram
New Golang malware is hijacking Telegram to help itself spread
Close up of the Linux penguin.
A new Linux backdoor is hitting US universities and governments
China
Chinese hackers develop effective new hacking technique to go after business networks
Mustang Panda
Chinese hackers abuse Microsoft tool to get past antivirus and cause havoc
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Juniper VPN gateways targeted by stealthy "magic" malware
GitHub Webpage
A cracked malicious version of a Go package lay undetected online for years
Latest in Pro
An image of network security icons for a network encircling a digital blue earth.
Why multi-CDNs are going to shake up 2025
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Millwall FC The Den
The UK's first football club mobile network is here - but you probably won't guess which team has launched it
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
Latest in News
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound