GoldMax

MITRE ATT&CK: S0588 View on attack.mitre.org

Aliases: SUNSHUTTLE, GoldMax

First seen
2019-06-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows, linux
Profile updated
2026-07-07 12:58:55

Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:us country_code:ca country_code:gb country_code:de

Context

GoldMax is a second-stage C2 backdoor written in Go with Windows and Linux variants that are nearly identical in functionality. GoldMax was discovered in early 2021 during the investigation into the SolarWinds Compromise, and has likely been used by APT29 since at least mid-2019. GoldMax uses multiple defense evasion techniques, including avoiding virtualization execution and masking malicious traffic.

Detection coverage

  • 1 YARA rules
  • 212 Sigma rules

Malware & tools used

  • Software Packing (attack-pattern)
  • Ignore Process Interrupts (attack-pattern)
  • System Time Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Cron (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Junk Data (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Web Protocols (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Time Based Checks (attack-pattern)
  • System Checks (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Scheduled Task (attack-pattern)

Used by threat actors

  • SolarWinds Compromise (campaign)
  • APT29 (threat-actor)

Detection rules

  • DITEKSHEN_MALWARE_Win_Sunshuttle (yara-rule)

Reports & references

  • Microsoft — Goldmax Goldfinder Sibot Analyzing Nobelium Malware (report)
  • Mandiant — Sunshuttle Second Stage Backdoor Targeting Us Based Entity (report)
  • CISA — Aa22 110A (report)
  • Kaspersky — 110355 (report)
  • Kaspersky — 109552 (report)
  • CrowdStrike — Observations From The Stellarparticle Campaign (report)
  • CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
  • ics-cert.kaspersky.com — Kaspersky Ics Cert Apt Attacks On Industrial Organizations In H1 2021 En (report)
  • umbrella.cisco.com — Cybersecurity Threat Spotlight Backdoors Rats Loaders Evasion Techniques (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Goldmax (report)
  • Kaspersky — 104715 (report)
  • youtube.com — Watch (report)
  • x0r19x91.gitlab.io — Sunshuttle (report)
  • CISA — Ar21 105A (report)
  • MITRE ATT&CK — S0588 (report)

External references