Gold Dragon

MITRE ATT&CK: S0249 View on attack.mitre.org

Aliases: Gold Dragon

First seen
2017-07-01 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:18:46

Targeted industries: government-and-public-sector media-and-entertainment

Targeted regions: country_code:kr

Context

Gold Dragon is a Korean-language, data gathering implant that was first observed in the wild in South Korea in July 2017. Gold Dragon was used along with Brave Prince and RunningRAT in operations targeting organizations associated with the 2018 Pyeongchang Winter Olympics.

Detection coverage

  • 1 YARA rules
  • 437 Sigma rules

Malware & tools used

  • Disable or Modify Tools (attack-pattern)
  • File Deletion (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Process Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Query Registry (attack-pattern)

Used by threat actors

Detection rules

  • ARKBIRD_SOLG_APT_Kimsuky_Aug_2020_1 (yara-rule)

Reports & references

  • McAfee — Gold Dragon Widens Olympics Malware Attacks Gains Permanent Presence On Victims Systems (report)
  • MITRE ATT&CK — S0249 (report)

External references