GoldenJackal
- First seen
- 2019-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:48:54
Targeted industries: government-and-public-sector technology-and-telecommunications education-and-nonprofits
Targeted regions: country_code:ru country_code:az country_code:tr
Context
GoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic. Kaspersky believes the attackers upload a malicious PHP file that is used as a relay to forward web requests to another backbone C2 server. They developed a collection of .NET malware tools known as Jackal.
Reports & references
- bsi.bund.de — Aktive Apt Gruppen Node (report)
- Kaspersky — 110355 (report)
- Kaspersky — 109677 (report)