yankywilson/gamybear
First public reverse engineering of GAMYBEAR, the Go backdoor used by UAC-0241 against Ukrainian education and state-authority targets. Static + dynamic analysis with 15 findings extending CERT-UA#18329, including a persistence correction and the http.DefaultClient TLS failure. IOCs, YARA, Suricata, Snort, STIX.
GitHub repository with 18 stars and 17 forks.
Language: Go
Topics: apt, gamybear, malware-analysis, reverse-engineering