GoldenEagle is an Android spyware family with samples dating to at least 2012. It has been used in China-linked mobile surveillance campaigns primarily targeting Uyghurs, including diaspora communities, and, at the broader campaign level, Tibetans. It belongs to an interconnected surveillance toolkit that includes SilkBean, DoubleAgent, and CarbonSteal and has been associated with GREF, also known as APT15.
GoldenEagle embeds malicious functionality in legitimate applications, including Uyghur community applications, VPN clients, instant messaging and social networking applications, games, adult media applications, and search utilities. These trojanized applications retain legitimate functionality while adding concealed surveillance capabilities. Distribution has involved phishing and third-party application channels rather than Google Play.
The malware collects SMS messages, contacts, call logs, and installed application names. It retrieves documents, text files, images, audio, Android application packages, and database files from external storage, and can take photographs using the device camera. GoldenEagle can also send SMS messages to an attacker-controlled number. It uses HTTP POST requests for command-and-control communications and exfiltrates collected data through both HTTP and SMTP.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GoldenEagle samples are reported from as early as 2012, which makes it one of the longer-running families in the set.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The surveillance apps of these campaigns were likely distributed through a combination of targeted phishing and fake third-party app stores.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android surveillance family linked to the same mobile espionage cluster as SilkBean, DoubleAgent, and CarbonSteal. An exposed administration panel revealed GPS coordinates assessed as belonging to early test devices; its infrastructure also supported phishing.
Android surveillanceware used in larger China-linked mobile APT campaigns to gather and exfiltrate personal user data to attacker-operated command-and-control servers; many samples were trojanized legitimate apps.
GoldenEagle is an Android surveillanceware used by APT15 for espionage against targeted individuals.
Surveillanceware family discussed in relation to shared/adjacent infrastructure with DoubleAgent activity and links inferred from insecure C2/admin-panel artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.