GoldenEagle

MITRE ATT&CK: S0551 View on attack.mitre.org

Aliases: GoldenEagle

First seen
2012-01-01 00:00:00
Malware type
spyware
Family
Malware family
Related IoCs
2 (2 malicious)
Last IoC activity
2026-07-16 23:34:36
Profile updated
2026-07-07 14:04:53

Targeted industries: government-and-public-sector media-and-entertainment

Targeted regions: country_code:cn country_code:tr

Context

GoldenEagle is a piece of Android malware that has been used in targeting of Uyghurs, Muslims, Tibetans, individuals in Turkey, and individuals in China. Samples have been found as early as 2012.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to GoldenEagle (S0551). The 2 most recently updated:

TypeIndicatorUpdatedSources
file sample zjcmcc_8.8.1_0913_1941_sign_3601.apk 2026-07-16 1
file sample 655a3d508c519f9632e88e748e048f1495636a4a6676909dbed823cd4d3d40a3 2026-05-02 1

Malware & tools used

  • Exfiltration Over C2 Channel (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Code Signing Policy Modification (attack-pattern)
  • Contact List (attack-pattern)
  • Web Protocols (attack-pattern)
  • Location Tracking (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • SMS Control (attack-pattern)
  • Video Capture (attack-pattern)
  • Audio Capture (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • System Information Discovery (attack-pattern)
  • SMS Messages (attack-pattern)
  • Software Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Call Log (attack-pattern)
  • Data from Local System (attack-pattern)

Reports & references

  • lookout.com — Lookout Uyghur Malware Tr Us (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Goldeneagle (report)
  • MITRE ATT&CK — S0551 (report)

External references