GoldMax, also known as SUNSHUTTLE, is a Go-based, second-stage command-and-control backdoor with Windows and Linux versions. It is associated with NOBELIUM, also known as APT29 and Cozy Bear, a cyberespionage group attributed to Russia’s Foreign Intelligence Service. GoldMax has been deployed after initial compromise in SUNBURST-related intrusions associated with the SolarWinds supply-chain operation. Its targeting includes government and other public- and private-sector organizations in North America and Europe.
GoldMax supports remote command execution, including native operating-system commands, transfer of additional tools onto compromised systems, and file exfiltration over its existing command-and-control channel. It enumerates network interfaces and retrieves system date and time information, which it can compare against a hardcoded execution trigger and transmit to its controller. Windows deployments maintain persistence through scheduled tasks while masquerading as legitimate systems-management software.
The backdoor stores an encrypted configuration on disk and decodes and decrypts it during execution, using implant-specific AES-256 keys. It also uses RSA encryption for command-and-control communications and implant-specific cookies to support operational identification. A decoy network-traffic generation feature blends malicious communications with benign-looking activity, supporting stealth and persistent access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GoldMax ... Command and Scripting Interpreter: Windows Command Shell ... Exfiltration Over C2 Channel ... Ingress Tool Transfer.
The malware presented in the workshop (Sunshuttle, from the DarkHalo APT, MD5 5DB340A70CB5D90601516DB89E629E43) is straightforward to the extent that it can be understood without paying too much attention to these objects.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
Examples include: "ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header," "UPPERCUT has used HTTP for C2, including sending error codes in Cookie headers," and "GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2."
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Their toolkit includes 7-Zip, AdFind, ATI-Agent, AtNow, BEATDROP, BloodHound, CEELOADER, CloudDuke, Cobalt Strike, CosmicDuke, CozyDuke, Danfuan, EnvyScout, FatDuke, FoggyWeb, GeminiDuke, Geppei, GoldFinder, GoldMax...
Backdoor referenced as similar to the Tomiris Golang backdoor; no further technical detail provided in this content.
Retrieves a list of system network interfaces after execution.
Malware implant identified in the content as one of the families used in the SolarWinds-related activity by NOBELIUM.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.