Goldbackdoor
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Stairwell found a new malware sample named “Goldbackdoor,” which was assessed as a successor of “Bluelight.”
For example, the threat actors targeted EU-based organizations with a new version of their mobile backdoor named 'Dolphin,' deployed a custom RAT (remote access trojan) called 'Konni,' and targeted U.S. journalists with a highly-customizable malware named 'Goldbackdoor.'
Techniques & procedures
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques
Initial Access
The second script downloads and executes a shellcode payload stored on Microsoft OneDrive, a legitimate cloud-based file hosting service... The malware utilizes legitimate cloud services for the exfiltration of files, with Stairwell noticing the abuse of both Google Drive and Microsoft OneDrive.
Execution
4 techniques
Execution
Upon execution, a PowerShell script launches... The second script downloads and executes a shellcode payload stored on Microsoft OneDrive
Upon execution, a PowerShell script launches and opens a decoy document (doc) for distraction while decoding a second script in the background.
Persistence
1 technique
Persistence
The second script downloads and executes a shellcode payload stored on Microsoft OneDrive, a legitimate cloud-based file hosting service... The malware utilizes legitimate cloud services for the exfiltration of files, with Stairwell noticing the abuse of both Google Drive and Microsoft OneDrive.
Privilege Escalation
1 technique
Privilege Escalation
Stealth
3 techniques
Stealth
The LNK file (Windows shortcut) is masqueraded with a document icon and uses padding to artificially increase its size to 282.7 MB
Credential Access
1 technique
Credential Access
Discovery
1 technique
Discovery
Collection
1 technique
Collection
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A highly customizable backdoor malware used by APT37 to target U.S. journalists.
Backdoor used in targeted surveillance operations by DPRK-linked actors.
A backdoor used in a highly targeted APT37 phishing campaign against journalists. It is executed as a PE file, accepts remote commands, performs keylogging, file operations, basic remote code execution, can uninstall itself, and exfiltrates data via legitimate cloud services including Google Drive and Microsoft OneDrive.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.