GoldDragon
Aliases: Lovexxx
- First seen
- 2017-12-01 00:00:00
- Malware type
- backdoor
- Profile updated
- 2026-07-07 12:51:42
Targeted industries: government-and-public-sector
Targeted regions: country_code:kr
Context
GoldDragon was a second-stage backdoor which established a permanent presence on the victim’s system once the first-stage, file-less, PowerShell-based attack leveraging steganography was executed. The initial attack was observed first in December 2017, when a Korean-language spear phishing campaing targeted organizations linked with Pyeongchang Winter Olympics 2018. GoldDragon was delivered once the attacker had gained an initial foothold in the targeted environment. The malware was capable of a basic reconnaissance, data exfiltration and downloading of additional components from its C&C server.
Reports & references
- cybereason.com — Back To The Future Inside The Kimsuky Kgh Spyware Suite (report)
- youtube.com — Watch (report)
- i.blackhat.com — As 21 Kuo We Are About To Land How Clouddragon Turns A Nightmare Into Reality (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Gold Dragon (report)
- Cisco Talos — Kimsuky Abuses Blogs Delivers Malware (report)
- asec.ahnlab.com — 31089 (report)