Revisiting Voldemort, HealthKick, and GOVERSHELL: A Technical Retrospective
ID: dd0fffd9-6b78-5572-aa4c-a6b486a53e3d
STIX ID: report--dd0fffd9-6b78-5572-aa4c-a6b486a53e3d
Feed Name: Resources-2
This report analyzes three interrelated espionage toolsets—Voldemort, HealthKick (GOVERSHELL v1), and GOVERSHELL v2–v5—used from mid‑2024 to late‑2025 against Taiwanese semiconductor firms and international think tanks, detailing their spear‑phishing delivery chains, DLL sideloading persistence, diverse C2 mechanisms (notably Google Sheets as C2 for Voldemort, double‑fake TLS for HealthKick, and evolving HTTP/WebSocket/AES schemes for GOVERSHELL), signs of LLM-assisted development, and recommendations to validate defenses using the Picus Security Validation Platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
