GoldDragon is a Windows malware cluster associated primarily with the North Korean threat actor Kimsuky, also tracked as Thallium, Black Banshee, Velvet Chollima, APT43, Emerald Sleet, and Springtail. It has been used in targeted cyber-espionage operations against South Korea-related political, diplomatic, academic, media, think-tank, defense, and North Korea-focused individuals and organizations. Some reporting has also noted technical overlaps that led to comparisons or links with Lazarus tradecraft, but GoldDragon is most consistently described as part of Kimsuky activity.
GoldDragon has been deployed through multi-stage spearphishing infection chains that use themed lure documents, including macro-enabled Microsoft Word files and Hangeul documents, followed by HTML Application and Visual Basic Script stages. The operation has also used alternate script-bearing formats such as CHM files and abused legitimate blog platforms to host encoded payloads or victim-specific staging content. A notable feature of GoldDragon campaigns is strict server-side victim validation designed to reduce malware exposure: delivery infrastructure has checked intended-recipient parameters, validated client IP continuity across stages, filtered by operating system and user-agent, and redirected non-matching requests to benign content or legitimate websites.
The malware chain performs host profiling before final payload delivery, collecting system and user environment details to qualify victims and tailor follow-on stages. Final-stage GoldDragon payloads are Windows executables focused on information theft. Reported capabilities include collecting file listings, keylogging, stealing stored browser credentials, stealing browser cookies, capturing screenshots, and downloading additional payloads. Persistence has been achieved through mechanisms including scheduled tasks. GoldDragon operations have also relied on layered command-and-control infrastructure distributed across commercial hosting providers and per-victim staging to complicate analysis and detection.
GoldDragon fits Kimsuky’s broader long-running espionage mission, which has emphasized credential theft and intelligence collection aligned with North Korean strategic interests. Its tradecraft reflects an emphasis on carefully curated victim targeting, staged delivery, operational security, and durable post-compromise collection on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kimsuky’s GoldDragon cluster infection procedure ... While researching Kimsuky’s novel infection chain, grouped as a GoldDragon cluster ... The final stage is a Windows executable-type malware that is capable of stealing information from the victim such as file lists, user keystrokes, and stored web browser login credentials.
GoldDragon samples are linked to Lazarus by two main features: the reuse of a specific RC4 implementation...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
For instance, Kimsuky was recently observed using an IP validation method as part of its GoldDragon infection mechanism. The same Intrusion Set also newly implemented a geofencing mechanism in their signature malware Konni RAT, and similar behaviour was observed in the FastSpy infection chain.
For instance, Kimsuky was recently observed using an IP validation method as part of its GoldDragon infection mechanism. The same Intrusion Set also newly implemented a geofencing mechanism in their signature malware Konni RAT, and similar behaviour was observed in the FastSpy infection chain.
156 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Kimsuky malware cluster delivered via spear-phishing documents, macros, HTA, and VBS stages. The final payload steals file lists, captures keystrokes, and extracts stored browser credentials, while earlier stages fingerprint victims and establish persistence via scheduled tasks.
A malware cluster used in a multi-stage Kimsuky intrusion chain to ultimately exfiltrate sensitive information including keyboard input, browser credentials/cookies, and screenshots.
Kimsuky malware/infection mechanism incorporating IP validation to screen targets.
Named malware used by Kimsuky and used to define one of the group's tracked subgroups in the report, but no technical behavior is detailed in this content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.