logo

Moscow-adjacent GoldenJackal gang strikes air-gapped systems with custom malware

ID: 0666cbf4-0975-5614-b21f-284e5ebd9cc2

STIX ID: report--0666cbf4-0975-5614-b21f-284e5ebd9cc2

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-10-09

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

GoldenJackal — a cyberespionage APT active since at least 2019 — used two separate custom toolsets (one set in 2019 and a newer Go-based set from 2022–2024) to target government and diplomatic organizations, including air-gapped systems via USB-mediated propagation and exploitation of vulnerabilities (e.g., Follina); ESET and Kaspersky linked multiple malware components (GoldenDealer, GoldenHowl, GoldenRobo, GoldenUsbCopy/Go, GoldenAce, GoldenBlacklist, GoldenMailer, GoldenDrive) and published IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.