#GoldBackdoor

Malware/Tool

2022-04-21 • The ink-stained trail of GOLDBACKDOOR

GOLDBACKDOOR is malware used in an APT37 spearphishing campaign against journalists covering North Korea. A compressed Windows shortcut disguised with a double-extension PDF filename executes obfuscated PowerShell, opens an embedded decoy document, retrieves encrypted shellcode from an attacker-controlled OneDrive location, decrypts it with XOR, and injects a second shellcode stage into a selected Windows executable. The backdoor inventories the computer name, operating system, internal and external IP addresses, antivirus status, and virtual-environment status. It communicates persistently through the Microsoft Graph API to transmit collected information, receive commands, execute CMD instructions, steal files, and log keystrokes. It has technical overlap with BLUELIGHT and may be its successor or a parallel tool.

Tagged Reports

« Back