Goldbackdoor is a custom Windows backdoor associated with the North Korean threat actor APT37, also tracked as ScarCruft, Reaper, RedEyes, Inky Squid, and Ricochet Chollima. It has been assessed as a successor to the BLUELIGHT malware family and has been used in targeted espionage operations against journalists covering North Korea, as well as in broader surveillance activity against civil-society and politically relevant targets.
Observed campaigns used spearphishing to deliver archive files containing oversized LNK shortcuts disguised as documents. Execution of the shortcut launched PowerShell-based staging that displayed a decoy document, decoded additional scripts, and retrieved a shellcode-based deployment component from cloud storage. Goldbackdoor has also been linked to related LNK-driven tradecraft seen in APT37 operations targeting South Korean interests.
The malware supports remote command execution, keylogging, file operations, self-removal, and exfiltration of victim data. It uses legitimate cloud services for command retrieval and data theft, including Microsoft and Google cloud platforms, and has been observed authenticating to Azure to obtain tasking. Deployment has relied on stealthy process-injection techniques to execute the payload in memory and reduce visibility. Goldbackdoor fits APT37’s long-running pattern of bespoke, espionage-focused tooling designed for covert collection against high-value individuals and organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
REArchive: Reverse engineering APT37’s GOLDBACKDOOR dropper ... The ink-stained trail of GOLDBACKDOOR
また、直近ではLNKファイルを用いた攻撃も報告[10]されており、これらの特徴は本攻撃キャンペーンと類似しています。
For example, the threat actors targeted EU-based organizations with a new version of their mobile backdoor named 'Dolphin,' deployed a custom RAT (remote access trojan) called 'Konni,' and targeted U.S. journalists with a highly-customizable malware named 'Goldbackdoor.'
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The second script downloads and executes a shellcode payload stored on Microsoft OneDrive, a legitimate cloud-based file hosting service... The malware utilizes legitimate cloud services for the exfiltration of files, with Stairwell noticing the abuse of both Google Drive and Microsoft OneDrive.
Upon execution, a PowerShell script launches... The second script downloads and executes a shellcode payload stored on Microsoft OneDrive
The PowerShell extracts a document file from the LNK, drops it to the disk, and then opens it... The PowerShell extracts a BAT script from the LNK, drops it to the disk, and executes it.
The second script downloads and executes a shellcode payload stored on Microsoft OneDrive, a legitimate cloud-based file hosting service... The malware utilizes legitimate cloud services for the exfiltration of files, with Stairwell noticing the abuse of both Google Drive and Microsoft OneDrive.
The LNK file (Windows shortcut) is masqueraded with a document icon and uses padding to artificially increase its size to 282.7 MB
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An APT37-linked backdoor/dropper family discussed in reverse-engineering and tracking reports.
A custom backdoor associated with the same actor as ROKRAT and delivered through a very similar oversized-LNK infection chain using PowerShell and decoy documents.
A highly customizable backdoor malware used by APT37 to target U.S. journalists.
Backdoor used in targeted surveillance operations by DPRK-linked actors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.