SYMBOL | COMMON_NAME | aka. SYNONYMS |
GoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic. Kaspersky believes the attackers upload a malicious PHP file that is used as a relay to forward web requests to another backbone C2 server. They developed a collection of .NET malware tools known as Jackal.
There are currently no families associated with this actor.
2023-08-30
⋅
Kaspersky Labs
⋅
IT threat evolution in Q2 2023 3CX Backdoor Bankshot BLINDINGCAN GoldMax Kazuar QUIETCANARY tomiris GoldenJackal |
2023-05-23
⋅
Kaspersky Labs
⋅
Meet the GoldenJackal APT group. Don’t expect any howls Jackal GoldenJackal |