GOLDBACKDOOR

Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 15:03:33

Context

GOLDBACKDOOR is a backdoor malware designed to provide unauthorized access to compromised systems. It is often used by threat actors for espionage, data exfiltration, and other malicious activities.

Detection coverage

  • 4 YARA rules

Detection rules

  • SIGNATURE_BASE_EXT_NK_GOLDBACKDOOR_Inital_Shellcode (yara-rule)
  • SIGNATURE_BASE_EXT_NK_GOLDBACKDOOR_Injected_Shellcode (yara-rule)
  • SIGNATURE_BASE_EXT_NK_GOLDBACKDOOR_Generic_Shellcode (yara-rule)
  • SIGNATURE_BASE_MAL_GOLDBACKDOOR_LNK (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Goldbackdoor (report)
  • stairwell.com — Stairwell Threat Report The Ink Stained Trail Of Goldbackdoor (report)
  • github.com — Stairwell Threat Report The Ink Stained Trail Of Goldbackdoor (report)
  • 0x0v1.com — Rearchive Goldbackdoor (report)

External references