GoldFinder

MITRE ATT&CK: S0597 View on attack.mitre.org

Aliases: GoldFinder

First seen
2021-01-01 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:58:53

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

GoldFinder is a custom HTTP tracer tool written in Go that logs the route a packet takes between a compromised network and a C2 server. It can be used to inform threat actors of potential points of discovery or logging of their actions, including C2 related to other malware. GoldFinder was discovered in early 2021 during an investigation into the SolarWinds Compromise by APT29.

Detection coverage

  • 35 Sigma rules

Malware & tools used

  • Automated Collection (attack-pattern)
  • Web Protocols (attack-pattern)
  • Internet Connection Discovery (attack-pattern)

Used by threat actors

  • SolarWinds Compromise (campaign)
  • APT29 (threat-actor)

Reports & references

  • Microsoft — Goldmax Goldfinder Sibot Analyzing Nobelium Malware (report)
  • MITRE ATT&CK — S0597 (report)

External references