Skip to content

Malware

Lyceum Golang HTTP Backdoor

This Golang written malware is used as backdoor using the http protocol by a state sponsored threat actor (TA).

Lyceum Golang HTTP Backdoor is a Windows malware family operated by LYCEUM.

Background

A state-sponsored threat actor (TA) employs this Golang-based malware as a backdoor that talks over the HTTP protocol. It cycles through three repeating stages:

  • Check the connectivity
  • Registration of the victim
  • Retrieval and execution of commands The same TA also makes use of .NET backdoor variants that rely on HTTP and DNS.

Source: Malpedia (Fraunhofer FKIE).