GoldenJackal

First seen
2019-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Profile updated
2026-07-07 11:48:54

Targeted industries: government-and-public-sector technology-and-telecommunications education-and-nonprofits

Targeted regions: country_code:ru country_code:az country_code:tr

Context

GoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic. Kaspersky believes the attackers upload a malicious PHP file that is used as a relay to forward web requests to another backbone C2 server. They developed a collection of .NET malware tools known as Jackal.

Reports & references

  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • Kaspersky — 110355 (report)
  • Kaspersky — 109677 (report)

External references