Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Gorilla

Also known as: Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Gamaredon APT, REvil

Description

Gorilla (APT 39/Chafer/REvil) combines the stealthy attributes of a well‑architected Go backdoor with aggressive revenue‑generating tactics such as DoS‑as‑a‑service and Magecart skimming. The actor ships its command‑and‑control via standard HTTP/S traffic interleaved with WebSocket (WSS) streams, often leveraging the Gorilla mux router to expose APIs that can be invoked directly by compromised hosts or through malicious attachments. Gorilla’s operational playbook includes exploitation of public-facing application vulnerabilities and privilege escalation vectors driven by unpatched software. After gaining footholds it typically compromises accounts for persistence, uses remote service connections for lateral movement, and employs social engineering (smishing/vishing) to spread phishing campaigns or fake mobile applications for credential harvesting. The threat actor’s toolset is eclectic, featuring widely used post‑exploitation frameworks such as Cobalt Strike and Sliver alongside bespoke malware families like ReGeorg and the BRICKSTORM backdoor. It frequently injects Magecart skimming scripts into merchants’ e‑commerce pages via Drive‑by downloads or malicious attachments. Overall Gorilla operates with a global footprint, regularly shifting domains and employing obfuscation techniques to evade detection, while remaining focused on financial gain across diverse sectors including finance, government, defense, telecom, retail, and critical infrastructure.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Telecommunications
Retail
Non profit
Critical infrastructure
Media
Energy
Education
Maritime
Healthcare
Gaming
Food agriculture
Transportation
Manufacturing
Utilities
Hospitality

Targeted Countries / Regions

CN
UA
RU
US
SA
PK
TW
AE
KR
MX
ES
IN
KP
AZ
AU
NL
IR
BY
GB

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Gorilla, also known as APT39, Chafer, REvil and several other aliases, is a financially motivated threat actor that deploys sophisticated web‑based C2 channels using Go’s Gorilla mux framework and hard‑coded domains, many of which resolve through Cloudflare Workers. It delivers client‑side exploits, exploits public applications, conducts lateral movement via remote services, and sells DoS‑as‑a‑service on Telegram. Its operations span multiple industries worldwide, targeting both commercial and critical infrastructure.

Goals & Targeting

Gorilla’s strategic objectives revolve primarily around monetization. By combining high‑profile DDoS services with targeted phishing campaigns and e‑skimming exploits it seeks to generate revenue through ransom demands, illicit data sale, and direct payments from compromised merchant sites. Its targeting profile is broad but weighted towards financially lucrative sectors such as retail, finance, and critical infrastructure, while also exploiting the political value of governmental or defense targets for influence operations. The actor often selects high‑value victims with publicly exposed services to ease initial compromises before moving laterally through remote service connections or credential compromise. Social engineering remains a key vector for initial access, especially via smishing/vishing and counterfeit mobile app distribution. Ultimately Gorilla aims to maximize return on investment by leveraging multiple attack vectors—DoS attacks, ransomware, data theft, and skim‑script infections—while minimizing exposure through domain hopping and the use of legitimate CDN services.

Enhanced Description

Key Capabilities

  • HTTP/HTTPS based command and control communications
  • WebSocket (WSS) C2 channels
  • API serving via gorilla/mux Go framework
  • Hardcoded c2 domains including Cloudflare Workers
  • Exploitation of public-facing application vulnerabilities
  • Delivery of client‑side exploits through malicious attachments or drive‑by downloads
  • Privilege escalation via unpatched flaws
  • Account compromise for persistence and remote access
  • Use of remote services for lateral movement
  • Smishing/Vishing social engineering campaigns
  • Fake mobile download & brand impersonation to install APKs
  • Magecart e‑skimming payload distribution on merchant sites

MITRE ATT&CK Tactics

Execution
Command and Control
Exploitation for Privilege Escalation
Persistence
Privilege Escalation
Defense Evasion
Discovery
Lateral Movement
Credential Access
Exfiltration
Impact

ATT&CK Techniques

T1543
T1133
T1003.002
T1071.004
T1489
T1071.005
T1071
T1005
T1140
T1190
T1036
T1572
T1021
T1071.003
T1090
T1059
T1070
T1083
T1568
T1586
T1102
T1057
T1041
T1071.002
T1678
T1574
T1078
T1068
T1027
T1486
T1690
T1573
T1203
T1132
T1071.001
T1105

Software / Tooling

Gorilla
REvil
Cobalt Strike
Sliver
PlugX
LightSpy
BlackEnergy
RedLine
BRICKSTORM backdoor
Nuclei
Havoc
Kazuar
Sofacy
Turbo
Winnti
OilRig
DragonForce
SolarWinds
MuddyWater

Campaigns & Victims

Gorilla typically operates in short, high‑impact bursts, often aligning its attacks with major political or economic events to amplify noise. The actor’s known operations include large‑scale DDoS attacks advertised on Telegram channels, coordinated with phishing campaigns that drop skimmers into merchant sites via compromised vendor libraries. Victims are usually multinational companies in finance, defense, energy, and retail with a presence of public portals or e‑commerce platforms where Magecart can be inserted. The use of publicly available exploit frameworks combined with custom code allows rapid pivoting between campaigns. Notable incidents show Gorilla’s ability to hijack domain fronting services like Cloudflare Workers for C2 persistence and to switch domains at runtime, making attribution and takedown more challenging.

IOC Patterns

  • Hardcoded C2 domain list patterns
  • WebSocket endpoint URL/IP patterns
  • HTTP/HTTPS traffic to known domains
  • File names such as Node.js or msiexec.exe
  • Domain indicators like TEMP.Periscope, sslip.io, nip.io
  • Email addresses like security-advisories@github.com
  • E‑mail-based smishing messages

Recommended Actions

  • Implement strict outbound filtering of WebSocket and HTTP/HTTPS traffic to known malicious domains; use DNS sinkholing for cloud fronted C2 endpoints. Deploy multi‑factor authentication and least privilege on all user accounts, especially those with remote service access. Enforce static application security testing (SAST) and dynamic scanning (DAST) for public‑facing applications; patch CVEs promptly. Educate users on smishing/vishing tactics and train to verify the authenticity of mobile app downloads or email attachments. Use token‑based authentication and certificate pinning in web APIs to reduce susceptibility to DNS hijacking.

Suggested Tags

APT39
Chafer
Cadelspy
Remexi
ITG07
Gamaredon
REvil
Gorilla
DoS-as-a-service
Telegram-based-Actions
Go-Backdoor
WebSocket-C2
Magecart
Social Engineering

Confidence Assessment

The data supporting Gorilla’s capabilities comes from multiple intelligence reports citing both technical indicators (C2 domains, Go framework usage) and operational behaviors. However, attribution remains uncertain due to overlapping aliases and inconsistent naming; some linked tool lists may represent separate actors amalgamated under similar monikers. Key gaps include lack of definitive campaign timelines, incomplete victim scope confirmation, and no publicly confirmed financial impact figures. Consequently confidence is moderate: the core architectural attributes are credible while finer operational details require further corroboration.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Advanced Persistent Threat 39
  2. attack.mitre.org — Cited by web research for: T1005
  3. www.recordedfuture.com — Cited by web research for: T1486
  4. pmc.ncbi.nlm.nih.gov — Cited by web research for: journal.pgen

Intel Summary

36

Techniques

42

Tools

0

Campaigns

29

IOCs

0

Observed Data

14

Tactics

Tags

DDoS
cybercrime
DoS-as-a-service
APT39
Chafer
Cadelspy
Remexi
ITG07
Gamaredon
REvil
Gorilla
Telegram-based-Actions
Go-Backdoor
WebSocket-C2
Magecart
Social Engineering

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.