Gosar

Malware

⚠️ Overview

Gosar is a Trojan horse first documented by the Israeli National Cyber Directorate in 2021, attributed to the Iranian advanced persistent threat group APT33 (also known as Elfin, Magnallium, or Refined Kitten). It is categorized as a custom backdoor used primarily for intelligence gathering and network reconnaissance, often delivered as a second-stage payload following the compromise of internet-facing Microsoft Exchange servers via CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 (collectively known as ProxyLogon).

🔧 Technical Capabilities

Gosar functions as a lightweight backdoor that provides remote shell access and file transfer capabilities. It uses HTTP for command-and-control (C2) communication, employing a custom encryption scheme with a hardcoded XOR key (0x8A, 0xC1, 0xE8, 0x5F) to obfuscate traffic. Persistence is achieved by creating a scheduled task named "OneDriveUpdateTask" or by modifying the registry key HKLMSoftwareMicrosoftWindowsCurrentVersionRun. The malware evades detection by masquerading as legitimate Windows files such as "svchost.exe" and by using API unhooking to bypass common endpoint protections. It can execute arbitrary commands, upload and download files, and perform process enumeration to identify security software. Propagation is manual — the operator deploys Gosar after initial access is gained through exploiting vulnerable Exchange servers.

📜 History & Notable Incidents

Gosar was first publicly reported in March 2021 by ClearSky Cyber Security, which linked its use to APT33 during the widespread exploitation of ProxyLogon vulnerabilities. In July 2021, the US Cybersecurity and Infrastructure Security Agency (CISA) included Gosar in its joint advisory with FBI, noting that the group targeted a range of organizations including US defense contractors, Israeli think tanks, and Middle Eastern government entities. No law enforcement actions have been publicly documented against the operators as of 2025.

🔍 Detection Indicators

Known file hashes include SHA-256: 2a3b5c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b (from ClearSky report). Network indicators include C2 traffic with User-Agent strings "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36" and HTTP POST requests to "/gate.php" with encrypted payloads. The mutex name "GlobalGosarMutex" has been observed, and the scheduled task "OneDriveUpdateTask" is a persistence indicator. Registry artifacts include a Run key value named "OneDriveUpdate" pointing to the malware binary.

☠️ Risk & Impact

Gosar enables persistent remote access, allowing threat actors to exfiltrate sensitive intellectual property, credentials, and email data. Industry sectors most affected include defense, energy, telecommunications, and academic institutions. While financial losses are not publicly quantified, the malware is a key tool in espionage campaigns that have compromised servers of notable Israeli think tanks (e.g., Interdisciplinary Center Herzliya) and US technology companies.

🛡️ Mitigation

Organizations should apply security updates for Exchange Server vulnerabilities (CVEs 2021-26855 through 2021-27065) immediately, enable multi-factor authentication, and deploy EDR solutions with behavioral detection rules for anomalous scheduled task creation and process injection. CISA recommends using the Microsoft Safety Scanner and reviewing Exchange server logs for unusual mailbox access or webshell deployments.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.