GoldMax

S0588

Malware.View on attack.mitre.org

About this malware

GoldMax is a second-stage C2 backdoor written in Go with Windows and Linux variants that are nearly identical in functionality. GoldMax was discovered in early 2021 during the investigation into the SolarWinds Compromise, and has likely been used by APT29 since at least mid-2019. GoldMax uses multiple defense evasion techniques, including avoiding virtualization execution and masking malicious traffic.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1001.001
Junk Data

GoldMax has used decoy traffic to surround its malicious network traffic to avoid detection.

T1016
System Network Configuration Discovery

GoldMax retrieved a list of the system's network interface after execution.

T1027.002
Software Packing

GoldMax has been packed for obfuscation.

T1027.013
Encrypted/Encoded File

GoldMax has written AES-encrypted and Base64-encoded configuration files to disk.

T1036.004
Masquerade Task or Service

GoldMax has impersonated systems management software to avoid detection.

T1036.005
Match Legitimate Resource Name or Location

GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder.

T1041
Exfiltration Over C2 Channel

GoldMax can exfiltrate files over the existing C2 channel.

T1053.003
Cron

The GoldMax Linux variant has used a crontab entry with a @reboot line to gain persistence.

T1053.005
Scheduled Task

GoldMax has used scheduled tasks to maintain persistence.

T1059.003
Windows Command Shell

GoldMax can spawn a command shell, and execute native commands.

T1071.001
Web Protocols

GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2.

T1105
Ingress Tool Transfer

GoldMax can download and execute additional files.

T1124
System Time Discovery

GoldMax can check the current date-time value of the compromised system, comparing it to the hardcoded execution trigger and can send the current timestamp to the C2 server.

T1140
Deobfuscate/Decode Files or Information

GoldMax has decoded and decrypted the configuration file when executed.

T1497.001
System Checks

GoldMax will check if it is being run in a virtualized environment by comparing the collected MAC address to c8:27:cc:c2:37:5a.

View all 18 procedure examples

Groups that use it1

Campaigns1

References3

  1. CrowdStrike StellarParticle January 2022 Open source
    CrowdStrike. (2022, January 27). Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign. Retrieved February 7, 2022.
  2. FireEye SUNSHUTTLE Mar 2021 Open source
    Smith, L., Leathery, J., Read, B. (2021, March 4). New SUNSHUTTLE Second-Stage Backdoor Uncovered Targeting U.S.-Based Entity; Possible Connection to UNC2452. Retrieved March 12, 2021.
  3. MSTIC NOBELIUM Mar 2021 Open source
    Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.