Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GoldenJackal

Description

GoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic. Kaspersky believes the attackers upload a malicious PHP file that is used as a relay to forward web requests to another backbone C2 server. They developed a collection of .NET malware tools known as Jackal.

AI Analysis

· 1 week ago

Executive Summary

GoldenJackal is a threat actor known for compromising WordPress websites to host command-and-control (C2) infrastructure. They utilize malicious PHP files to relay web requests to their main C2 servers and have developed .NET malware tools called Jackal. Their activities suggest moderate sophistication with a focus on persistence and data exfiltration.

Goals & Targeting

GoldenJackal's strategic objectives likely include long-term persistence within targeted networks and the establishment of reliable C2 channels, enabling sustained operations and data collection. Their targeting profile suggests a focus on sectors with web-based assets, such as educational institutions or small businesses, which may have less robust security measures in place. The use of WordPress sites—commonly used across various industries—as a vector indicates a broad targeting approach.

Enhanced Description

GoldenJackal's operations involve compromising WordPress sites as part of their attack chain, using these platforms to host malicious PHP files that act as relays to communicate with their primary C2 infrastructure. This method allows them to maintain persistence and control over infected systems. Kaspersky has identified their development of Jackal, a collection of .NET-based malware tools, which likely aids in various stages of their attacks, including initial compromise, lateral movement, and data exfiltration. The use of such tools indicates that GoldenJackal possesses at least moderate technical expertise and an ability to develop custom solutions for their malicious activities.

Key Capabilities

  • Malware development (Jackal)
  • Compromise of web applications
  • Use of command-and-control relay infrastructure
  • Persistent C2 communication

MITRE ATT&CK Tactics

Initial Access
Execution
Defense-Evasion
Lateral Movement

ATT&CK Techniques

T1059.003 - Command-line interface arguments
T1284 - Web-based Communication
T1071.001 - Web Shell Creation via DLL Injection

Software / Tooling

Jackal (DOTNET)
Custom PHP Malware

Campaigns & Victims

GoldenJackal's campaigns leverage web application compromise for persistence, indicating a focus on long-term operations. Their use of .NET malware and relay servers suggests they are targeting sectors with significant digital assets but less mature security frameworks. Notable past operations include multiple compromises of WordPress sites to host their C2 infrastructure, though specific operations remain unlinked in the provided intelligence.

IOC Patterns

  • Malicious PHP files uploaded to compromised WordPress sites
  • Unusual web traffic patterns from WordPress domains
  • DNS queries resolving to known GoldenJackal domains

Recommended Actions

  • Implement regular patching of WordPress sites and underlying servers
  • Monitor for unusual PHP file changes in web directories
  • Deploy network monitoring to detect C2 relay activities
  • Conduct periodic security assessments of web assets

Suggested Tags

Malware
APT-like
Web Attack
.NET Exploitation

Confidence Assessment

Confidence in the assessment is moderate. While their TTPs are well-documented, specific motivations, target countries, and campaign history remain unclear. Additional data on their geographic targeting or associated campaigns would enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
Malware
APT-like
Web Attack
.NET Exploitation

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.