GoldFinder
MITRE ATT&CK: S0597 View on attack.mitre.org
Aliases: GoldFinder
- First seen
- 2021-01-01 00:00:00
- Malware type
- spyware
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:58:53
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
GoldFinder is a custom HTTP tracer tool written in Go that logs the route a packet takes between a compromised network and a C2 server. It can be used to inform threat actors of potential points of discovery or logging of their actions, including C2 related to other malware. GoldFinder was discovered in early 2021 during an investigation into the SolarWinds Compromise by APT29.
Detection coverage
- 35 Sigma rules
Malware & tools used
- Automated Collection (attack-pattern)
- Web Protocols (attack-pattern)
- Internet Connection Discovery (attack-pattern)
Used by threat actors
- SolarWinds Compromise (campaign)
- APT29 (threat-actor)
Reports & references
- Microsoft — Goldmax Goldfinder Sibot Analyzing Nobelium Malware (report)
- MITRE ATT&CK — S0597 (report)