GOLDVEIN is a downloader used in multi-stage attacks against enterprise applications. Its PowerShell implementation was first observed in December 2024 during exploitation of Cleo managed file transfer products, including LexiCom, VLTrader, and Harmony. Attackers deployed it through unauthenticated remote code execution vulnerabilities alongside the modular GOLDTOMB toolkit.
GOLDVEIN.JAVA is a Java variant observed in 2025 attacks against Oracle E-Business Suite involving CVE-2025-61882. It receives second-stage payloads from a command-and-control server and operates in memory, using communications disguised as TLS handshakes. Bash processes launched by this variant were used to execute reconnaissance commands on compromised systems.
GOLDVEIN has appeared in enterprise data-theft campaigns associated with FIN11 tooling and Cl0p-branded extortion. These operations target internet-facing applications holding sensitive business information. The downloader provides a foothold for subsequent malware deployment; data theft, persistence, and extortion performed elsewhere in these attack chains are not established as intrinsic GOLDVEIN capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Operating around December 2024, the actors utilized unauthenticated remote execution vulnerabilities to introduce GOLDVEIN, a malicious downloader, alongside the modular toolkit GOLDTOMB.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Operating around December 2024, the actors utilized unauthenticated remote execution vulnerabilities to introduce GOLDVEIN, a malicious downloader, alongside the modular toolkit GOLDTOMB.
Operating around December 2024, the actors utilized unauthenticated remote execution vulnerabilities to introduce GOLDVEIN, a malicious downloader, alongside the modular toolkit GOLDTOMB.
Operating around December 2024, the actors utilized unauthenticated remote execution vulnerabilities to introduce GOLDVEIN, a malicious downloader, alongside the modular toolkit GOLDTOMB.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious downloader used in attacks against Cleo enterprise file-transfer products. The content also describes a Java variant, GOLDVEIN.JAVA, deployed in Oracle E-Business Suite compromises and beaconing through mock TLS handshakes.
A dropper malware family observed in the Oracle E-Business Suite attack chains.
GOLDVEIN is a downloader malware, originally a PowerShell script, now also seen as a Java variant, used to fetch and execute second-stage payloads from a C2 server.
Multi-stage Java in-memory implant used in the Oracle E-Business Suite exploitation/extortion activity; stored in the EBS database and communicates to C2 while masquerading as TLS handshakes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.