216.73.217.80

Mind the (air) gap: GoldenJackal gooses government guardrails

· Published 17/11/2024 00:25 · Modified 18/11/2024 17:03

Export JSON

Essential information

Published
17/11/2024 00:25
Modified
18/11/2024 17:03
Tags
2024-11-17 air-gapped systems apt cyberespionage goldenace goldenblacklist goldendealer goldendrive goldenhowl goldenmailer goldenpyblacklist goldenrobo goldenusbcopy goldenusbgo jackalworm modular malware usb propagation
Related entities
1 intrusion sets (apt), 11 malware, 2 others

Description

ESET researchers uncovered two distinct toolsets used by the GoldenJackal group to breach in government organizations. The first toolset, observed in 2019, included for delivering executables via USB drives, as a modular backdoor, and for file collection and exfiltration. The second toolset, deployed from 2022 to 2024, featured a highly modular approach with components for file collection, distribution, and exfiltration. GoldenJackal primarily targeted government and diplomatic entities in Europe, the Middle East, and South Asia, demonstrating sophisticated capabilities to compromise isolated networks. The group's evolution in developing two separate air-gap breaching toolsets within five years highlights their advanced threat level and awareness of network segmentation practices employed by their targets.

External references