Also known as: SUNSHUTTLE
Executive Summary
GoldMax is a Go-based, cross‑platform backdoor linked to APT29 that was discovered during the SolarWinds breach. It uses virtualization detection and traffic masking to evade analysis and remain hidden from baseline defenses. The presence of both Windows and Linux variants indicates a broader attack surface and persistent capabilities.
Enhanced Description
GoldMax, also known as SUNSHUTTLE, is a sophisticated second‑stage command and control (C2) backdoor that was first identified in early 2021 during the SolarWinds investigation. Written in Go, GoldMax ships with nearly identical Windows and Linux variants, enabling it to persist across heterogeneous environments while reducing the forensic footprint associated with language diversity. The malware demonstrates a high degree of stealth through multiple defense evasion techniques. It explicitly checks for virtualization indicators before execution, thwarting sandbox analysis, and it employs traffic masking mechanisms—such as custom encryption and protocol obfuscation—that camouflage malicious network activity within legitimate application layer channels. GoldMax’s operational profile aligns with the tactics attributed to APT29; it is presumed to have been in use since at least mid‑2019. Its dual‑platform footprint, combined with proven C2 robustness, suggests integration into long‑term espionage campaigns targeting high‑value organizations across sectors.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on limited public citations (MSTIC, FireEye, CrowdStrike) with unspecified first/last seen dates and no detailed technical breakdowns. While the cross‑platform description and attribution to APT29 are well supported, granular capabilities, persistence mechanisms, and full impact assessment remain partially inferred.
GoldMax is a second-stage C2 backdoor written in Go with Windows and Linux variants that are nearly identical in functionality. GoldMax was discovered in early 2021 during the investigation into the SolarWinds Compromise, and has likely been used by APT29 since at least mid-2019. GoldMax uses multiple defense evasion techniques, including avoiding virtualization execution and masking malicious traffic.(Citation: MSTIC NOBELIUM Mar 2021)(Citation: FireEye SUNSHUTTLE Mar 2021)(Citation: CrowdStrike StellarParticle January 2022)