Gold Dragon
MITRE ATT&CK: S0249 View on attack.mitre.org
Aliases: Gold Dragon
- First seen
- 2017-07-01 00:00:00
- Malware type
- spyware
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:18:46
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:kr
Context
Gold Dragon is a Korean-language, data gathering implant that was first observed in the wild in South Korea in July 2017. Gold Dragon was used along with Brave Prince and RunningRAT in operations targeting organizations associated with the 2018 Pyeongchang Winter Olympics.
Detection coverage
- 1 YARA rules
- 437 Sigma rules
Malware & tools used
- Disable or Modify Tools (attack-pattern)
- File Deletion (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Local Data Staging (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Archive Collected Data (attack-pattern)
- Process Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Information Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Security Software Discovery (attack-pattern)
- Query Registry (attack-pattern)
Used by threat actors
- Kimsuky (threat-actor)
Detection rules
- ARKBIRD_SOLG_APT_Kimsuky_Aug_2020_1 (yara-rule)
Reports & references
- McAfee — Gold Dragon Widens Olympics Malware Attacks Gains Permanent Presence On Victims Systems (report)
- MITRE ATT&CK — S0249 (report)
External references
- mitre-attack — S0249
- Gold Dragon
- McAfee Gold Dragon
- misp-galaxy
- misp-galaxy