Moscow-adjacent GoldenJackal gang strikes air-gapped systems with custom malware
ID: 0666cbf4-0975-5614-b21f-284e5ebd9cc2
STIX ID: report--0666cbf4-0975-5614-b21f-284e5ebd9cc2
Feed Name: The Register (Security)
GoldenJackal — a cyberespionage APT active since at least 2019 — used two separate custom toolsets (one set in 2019 and a newer Go-based set from 2022–2024) to target government and diplomatic organizations, including air-gapped systems via USB-mediated propagation and exploitation of vulnerabilities (e.g., Follina); ESET and Kaspersky linked multiple malware components (GoldenDealer, GoldenHowl, GoldenRobo, GoldenUsbCopy/Go, GoldenAce, GoldenBlacklist, GoldenMailer, GoldenDrive) and published IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
