Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware GoldMax

GoldMax

TLP:CLEAR
Family

Also known as: SUNSHUTTLE

AI Analysis

· 8 hours ago

Executive Summary

GoldMax is a Go-based, cross‑platform backdoor linked to APT29 that was discovered during the SolarWinds breach. It uses virtualization detection and traffic masking to evade analysis and remain hidden from baseline defenses. The presence of both Windows and Linux variants indicates a broader attack surface and persistent capabilities.

Enhanced Description

GoldMax, also known as SUNSHUTTLE, is a sophisticated second‑stage command and control (C2) backdoor that was first identified in early 2021 during the SolarWinds investigation. Written in Go, GoldMax ships with nearly identical Windows and Linux variants, enabling it to persist across heterogeneous environments while reducing the forensic footprint associated with language diversity. The malware demonstrates a high degree of stealth through multiple defense evasion techniques. It explicitly checks for virtualization indicators before execution, thwarting sandbox analysis, and it employs traffic masking mechanisms—such as custom encryption and protocol obfuscation—that camouflage malicious network activity within legitimate application layer channels. GoldMax’s operational profile aligns with the tactics attributed to APT29; it is presumed to have been in use since at least mid‑2019. Its dual‑platform footprint, combined with proven C2 robustness, suggests integration into long‑term espionage campaigns targeting high‑value organizations across sectors.

Key Capabilities

  • Cross‑platform operation (Windows & Linux)
  • Virtualization/sandbox evasion via environment checks
  • Encrypted C2 communication with custom obfuscation
  • Stealthy traffic masking, blending into legitimate application channels

ATT&CK Techniques

T1063
T1071
T1059
T1497

Recommended Actions

  • Deploy signature and behavioral detection rules for Go binaries exhibiting virtualization checks and encrypted outbound traffic.
  • Implement network segmentation to isolate critical assets from external communications and monitor anomalous DNS or HTTP/HTTPS requests.
  • Enforce host‑based EDR solutions that identify process injection or unusual cryptographic API usage.
  • Conduct regular vulnerability assessments for outdated endpoints that may be vulnerable to exploitation by GoldMax variants.

Suggested Tags

goldmax
sunshuttle
backdoor
apt29
solarwinds
cross-platform
golang

Confidence Assessment

The analysis is based on limited public citations (MSTIC, FireEye, CrowdStrike) with unspecified first/last seen dates and no detailed technical breakdowns. While the cross‑platform description and attribution to APT29 are well supported, granular capabilities, persistence mechanisms, and full impact assessment remain partially inferred.

Description

GoldMax is a second-stage C2 backdoor written in Go with Windows and Linux variants that are nearly identical in functionality. GoldMax was discovered in early 2021 during the investigation into the SolarWinds Compromise, and has likely been used by APT29 since at least mid-2019. GoldMax uses multiple defense evasion techniques, including avoiding virtualization execution and masking malicious traffic.(Citation: MSTIC NOBELIUM Mar 2021)(Citation: FireEye SUNSHUTTLE Mar 2021)(Citation: CrowdStrike StellarParticle January 2022)

Details

Type
Malware
Platforms
Windows
Linux
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.