ATT&CKSoftwareGold Dragon

Gold Dragon

S0249

Malware.View on attack.mitre.org

About this malware

Gold Dragon is a Korean-language, data gathering implant that was first observed in the wild in South Korea in July 2017. Gold Dragon was used along with Brave Prince and RunningRAT in operations targeting organizations associated with the 2018 Pyeongchang Winter Olympics.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1012
Query Registry

Gold Dragon enumerates registry keys with the command regkeyenum and obtains information for the Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

T1033
System Owner/User Discovery

Gold Dragon collects the endpoint victim's username and uses it as a basis for downloading additional components from the C2 server.

T1057
Process Discovery

Gold Dragon checks the running processes on the victim’s machine.

T1059.003
Windows Command Shell

Gold Dragon uses cmd.exe to execute commands for discovery.

T1070.004
File Deletion

Gold Dragon deletes one of its files, 2.hwp, from the endpoint after establishing persistence.

T1071.001
Web Protocols

Gold Dragon uses HTTP for communication to the control servers.

T1074.001
Local Data Staging

Gold Dragon stores information gathered from the endpoint in a file named 1.hwp.

T1082
System Information Discovery

Gold Dragon collects endpoint information using the systeminfo command.

T1083
File and Directory Discovery

Gold Dragon lists the directories for Desktop, program files, and the user’s recently accessed files.

T1105
Ingress Tool Transfer

Gold Dragon can download additional components from the C2 server.

T1518.001
Security Software Discovery

Gold Dragon checks for anti-malware products and processes.

T1547.001
Registry Run Keys / Startup Folder

Gold Dragon establishes persistence in the Startup folder.

T1560
Archive Collected Data

Gold Dragon encrypts data using Base64 before being sent to the command and control server.

T1685
Disable or Modify Tools

Gold Dragon terminates anti-malware processes if they’re found running on the system.

Groups that use it1

Campaigns0

None recorded.

References1

  1. McAfee Gold Dragon Open source
    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.