s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.gokcpdoor

📛 Threat Title

Malware family: gokcpdoor

Category: gokcpdoor First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.gokcpdoor`. Printable name: gokcpdoor.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.gokcpdoor VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gokcpdoor

IOC database

Type
domain
Value
elf.gokcpdoor
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.gokcpdoor

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gokcpdoor

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    After exploiting the vulnerability, the attackers established persistence by deploying a custom backdoor known as Gokcpdoor , observed in both server-type and client-type variants; the server variant acted as a listener while the client variant connected outbound to predefined command-and-control infrastructure.

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:dailysecurityreview.com

    Custom malware implants such as Daserf, xxmm, and Gokcpdoor The group's deployment of the Gokcpdoor malware via a vulnerable Japanese software platform fits a pattern of leveraging trusted regional tools for initial access, which allows operations to persist undetected for extended periods. Mitigation Guidance and Vendor Response

  • web:malpedia.caad.fkie.fraunhofer.de

    According to LAC, this malware is written in Go and was observed in 2022 used by an unknown China-based APT across several incidents in Japan. This backdoor has 20 commands and connects with C2 servers via KCP over UDP.

  • web:securityonline.info

    During the campaign, CTU identified the Gokcpdoor malware as the main backdoor used for command and control (C2). Previously observed in 2023, Gokcpdoor was known for using the KCP protocol to establish proxy connections.

  • web:www.bleepingcomputer.com

    China-linked cyber-espionage actors tracked as 'Bronze Butler' (Tick) exploited a Motex Lanscope Endpoint Manager vulnerability as a zero-day to deploy an updated version of their Gokcpdoor malware .

  • web:www.linkedin.com

    🚨 BRONZE BUTLER Exploits LANSCOPE Zero-Day - CVE-2025-61932 🚨 Chinese state-sponsored APT group BRONZE BUTLER (aka Tick) has launched a sophisticated campaign targeting Motex LANSCOPE ...

  • web:www.prsol.cc

    China-linked cyber-espionage actors tracked as 'Bronze Butler' (Tick) exploited a Motex Lanscope Endpoint Manager vulnerability as a zero-day to deploy an updated version of their Gokcpdoor malware . The discovery of this activity comes from Sophos researchers, who observed the threat actors exploiting the vulnerability in mid-2025 before it was patched to steal confidential information ...

  • web:www.thaicert.or.th

    440/68 Monday, November 3, 2025 Researchers from Sophos have reported that the cyber-espionage group Bronze Butler (also known as Tick) exploited a zero-day vulnerability in Motex Lanscope Endpoint Manager to distribute a new variant of the Gokcpdoor malware designed to steal confidential data from targeted organizations. The flaw, tracked as CVE-2025-61932, is a Request Origin

  • web:www.virusbulletin.com

    However, the newly confirmed (March 2022) gokcpdoor malware is different. This malware utilizes the kcp-go library to actually perform C2 communication with the KCP protocol. In the following, we will introduce the KCP implementation of each malware family . Figure 4: Timeline of malware families using KCP protocol.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.