TF-MAL-elf.gokcpdoor
📛 Threat Title
Malware family: gokcpdoor
Description
ThreatFox malware family `elf.gokcpdoor`. Printable name: gokcpdoor.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.gokcpdoor
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gokcpdoor
IOC database
- Type
- domain
- Value
elf.gokcpdoor- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.gokcpdoor
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gokcpdoor
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
After exploiting the vulnerability, the attackers established persistence by deploying a custom backdoor known as Gokcpdoor , observed in both server-type and client-type variants; the server variant acted as a listener while the client variant connected outbound to predefined command-and-control infrastructure.
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:dailysecurityreview.com
Custom malware implants such as Daserf, xxmm, and Gokcpdoor The group's deployment of the Gokcpdoor malware via a vulnerable Japanese software platform fits a pattern of leveraging trusted regional tools for initial access, which allows operations to persist undetected for extended periods. Mitigation Guidance and Vendor Response
-
web:malpedia.caad.fkie.fraunhofer.de
According to LAC, this malware is written in Go and was observed in 2022 used by an unknown China-based APT across several incidents in Japan. This backdoor has 20 commands and connects with C2 servers via KCP over UDP.
-
web:securityonline.info
During the campaign, CTU identified the Gokcpdoor malware as the main backdoor used for command and control (C2). Previously observed in 2023, Gokcpdoor was known for using the KCP protocol to establish proxy connections.
-
web:www.bleepingcomputer.com
China-linked cyber-espionage actors tracked as 'Bronze Butler' (Tick) exploited a Motex Lanscope Endpoint Manager vulnerability as a zero-day to deploy an updated version of their Gokcpdoor malware .
-
web:www.linkedin.com
🚨 BRONZE BUTLER Exploits LANSCOPE Zero-Day - CVE-2025-61932 🚨 Chinese state-sponsored APT group BRONZE BUTLER (aka Tick) has launched a sophisticated campaign targeting Motex LANSCOPE ...
-
web:www.prsol.cc
China-linked cyber-espionage actors tracked as 'Bronze Butler' (Tick) exploited a Motex Lanscope Endpoint Manager vulnerability as a zero-day to deploy an updated version of their Gokcpdoor malware . The discovery of this activity comes from Sophos researchers, who observed the threat actors exploiting the vulnerability in mid-2025 before it was patched to steal confidential information ...
-
web:www.thaicert.or.th
440/68 Monday, November 3, 2025 Researchers from Sophos have reported that the cyber-espionage group Bronze Butler (also known as Tick) exploited a zero-day vulnerability in Motex Lanscope Endpoint Manager to distribute a new variant of the Gokcpdoor malware designed to steal confidential data from targeted organizations. The flaw, tracked as CVE-2025-61932, is a Request Origin
-
web:www.virusbulletin.com
However, the newly confirmed (March 2022) gokcpdoor malware is different. This malware utilizes the kcp-go library to actually perform C2 communication with the KCP protocol. In the following, we will introduce the KCP implementation of each malware family . Figure 4: Timeline of malware families using KCP protocol.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.