GoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic. Kaspersky believes the attackers upload a malicious PHP file that is used as a relay to forward web requests to another backbone C2 server. They developed a collection of .NET malware tools known as Jackal.
Executive Summary
GoldenJackal is a threat actor known for compromising WordPress websites to host command-and-control (C2) infrastructure. They utilize malicious PHP files to relay web requests to their main C2 servers and have developed .NET malware tools called Jackal. Their activities suggest moderate sophistication with a focus on persistence and data exfiltration.
Goals & Targeting
GoldenJackal's strategic objectives likely include long-term persistence within targeted networks and the establishment of reliable C2 channels, enabling sustained operations and data collection. Their targeting profile suggests a focus on sectors with web-based assets, such as educational institutions or small businesses, which may have less robust security measures in place. The use of WordPress sites—commonly used across various industries—as a vector indicates a broad targeting approach.
Enhanced Description
GoldenJackal's operations involve compromising WordPress sites as part of their attack chain, using these platforms to host malicious PHP files that act as relays to communicate with their primary C2 infrastructure. This method allows them to maintain persistence and control over infected systems. Kaspersky has identified their development of Jackal, a collection of .NET-based malware tools, which likely aids in various stages of their attacks, including initial compromise, lateral movement, and data exfiltration. The use of such tools indicates that GoldenJackal possesses at least moderate technical expertise and an ability to develop custom solutions for their malicious activities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GoldenJackal's campaigns leverage web application compromise for persistence, indicating a focus on long-term operations. Their use of .NET malware and relay servers suggests they are targeting sectors with significant digital assets but less mature security frameworks. Notable past operations include multiple compromises of WordPress sites to host their C2 infrastructure, though specific operations remain unlinked in the provided intelligence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the assessment is moderate. While their TTPs are well-documented, specific motivations, target countries, and campaign history remain unclear. Additional data on their geographic targeting or associated campaigns would enhance understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics