Also known as: Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Gamaredon APT, REvil
Gorilla (APT 39/Chafer/REvil) combines the stealthy attributes of a well‑architected Go backdoor with aggressive revenue‑generating tactics such as DoS‑as‑a‑service and Magecart skimming. The actor ships its command‑and‑control via standard HTTP/S traffic interleaved with WebSocket (WSS) streams, often leveraging the Gorilla mux router to expose APIs that can be invoked directly by compromised hosts or through malicious attachments. Gorilla’s operational playbook includes exploitation of public-facing application vulnerabilities and privilege escalation vectors driven by unpatched software. After gaining footholds it typically compromises accounts for persistence, uses remote service connections for lateral movement, and employs social engineering (smishing/vishing) to spread phishing campaigns or fake mobile applications for credential harvesting. The threat actor’s toolset is eclectic, featuring widely used post‑exploitation frameworks such as Cobalt Strike and Sliver alongside bespoke malware families like ReGeorg and the BRICKSTORM backdoor. It frequently injects Magecart skimming scripts into merchants’ e‑commerce pages via Drive‑by downloads or malicious attachments. Overall Gorilla operates with a global footprint, regularly shifting domains and employing obfuscation techniques to evade detection, while remaining focused on financial gain across diverse sectors including finance, government, defense, telecom, retail, and critical infrastructure.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Gorilla, also known as APT39, Chafer, REvil and several other aliases, is a financially motivated threat actor that deploys sophisticated web‑based C2 channels using Go’s Gorilla mux framework and hard‑coded domains, many of which resolve through Cloudflare Workers. It delivers client‑side exploits, exploits public applications, conducts lateral movement via remote services, and sells DoS‑as‑a‑service on Telegram. Its operations span multiple industries worldwide, targeting both commercial and critical infrastructure.
Goals & Targeting
Gorilla’s strategic objectives revolve primarily around monetization. By combining high‑profile DDoS services with targeted phishing campaigns and e‑skimming exploits it seeks to generate revenue through ransom demands, illicit data sale, and direct payments from compromised merchant sites. Its targeting profile is broad but weighted towards financially lucrative sectors such as retail, finance, and critical infrastructure, while also exploiting the political value of governmental or defense targets for influence operations. The actor often selects high‑value victims with publicly exposed services to ease initial compromises before moving laterally through remote service connections or credential compromise. Social engineering remains a key vector for initial access, especially via smishing/vishing and counterfeit mobile app distribution. Ultimately Gorilla aims to maximize return on investment by leveraging multiple attack vectors—DoS attacks, ransomware, data theft, and skim‑script infections—while minimizing exposure through domain hopping and the use of legitimate CDN services.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Gorilla typically operates in short, high‑impact bursts, often aligning its attacks with major political or economic events to amplify noise. The actor’s known operations include large‑scale DDoS attacks advertised on Telegram channels, coordinated with phishing campaigns that drop skimmers into merchant sites via compromised vendor libraries. Victims are usually multinational companies in finance, defense, energy, and retail with a presence of public portals or e‑commerce platforms where Magecart can be inserted. The use of publicly available exploit frameworks combined with custom code allows rapid pivoting between campaigns. Notable incidents show Gorilla’s ability to hijack domain fronting services like Cloudflare Workers for C2 persistence and to switch domains at runtime, making attribution and takedown more challenging.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data supporting Gorilla’s capabilities comes from multiple intelligence reports citing both technical indicators (C2 domains, Go framework usage) and operational behaviors. However, attribution remains uncertain due to overlapping aliases and inconsistent naming; some linked tool lists may represent separate actors amalgamated under similar monikers. Key gaps include lack of definitive campaign timelines, incomplete victim scope confirmation, and no publicly confirmed financial impact figures. Consequently confidence is moderate: the core architectural attributes are credible while finer operational details require further corroboration.
No campaigns linked yet.
No observed data linked yet.
36
Techniques
42
Tools
0
Campaigns
29
IOCs
0
Observed Data
14
Tactics