GoldenEagle
MITRE ATT&CK: S0551 View on attack.mitre.org
Aliases: GoldenEagle
- First seen
- 2012-01-01 00:00:00
- Malware type
- spyware
- Family
- Malware family
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-07-16 23:34:36
- Profile updated
- 2026-07-07 14:04:53
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:cn country_code:tr
Context
GoldenEagle is a piece of Android malware that has been used in targeting of Uyghurs, Muslims, Tibetans, individuals in Turkey, and individuals in China. Samples have been found as early as 2012.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to GoldenEagle (S0551). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | zjcmcc_8.8.1_0913_1941_sign_3601.apk | 2026-07-16 | 1 |
| file sample | 655a3d508c519f9632e88e748e048f1495636a4a6676909dbed823cd4d3d40a3 | 2026-05-02 | 1 |
Malware & tools used
- Exfiltration Over C2 Channel (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Code Signing Policy Modification (attack-pattern)
- Contact List (attack-pattern)
- Web Protocols (attack-pattern)
- Location Tracking (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- SMS Control (attack-pattern)
- Video Capture (attack-pattern)
- Audio Capture (attack-pattern)
- Download New Code at Runtime (attack-pattern)
- System Information Discovery (attack-pattern)
- SMS Messages (attack-pattern)
- Software Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Stored Application Data (attack-pattern)
- Call Log (attack-pattern)
- Data from Local System (attack-pattern)
Reports & references
- lookout.com — Lookout Uyghur Malware Tr Us (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Goldeneagle (report)
- MITRE ATT&CK — S0551 (report)