GOLDVEIN.JAVA is a Java-based downloader used in large-scale exploitation of Oracle E-Business Suite environments and previously associated with activity overlapping suspected FIN11 and UNC5936 operations. It was prominently observed in 2025 intrusions tied to exploitation of Oracle EBS vulnerabilities, including CVE-2025-61882, and was also noted as reminiscent of earlier GOLDVEIN tooling used during exploitation of Cleo managed file transfer software.
In Oracle EBS compromises, GOLDVEIN.JAVA was embedded in malicious XSL payload chains installed in the target environment’s database and executed through abused XML Publisher template functionality. The malware beacons to attacker-controlled infrastructure using traffic disguised to resemble a TLS handshake and attempts to retrieve a second-stage payload. Reporting also indicates it can return execution logs within HTML comments, suggesting operator feedback and task verification during exploitation. The family was described as part of sophisticated, multi-stage, fileless tradecraft designed to evade file-based detection.
GOLDVEIN.JAVA functioned as an early-stage payload following successful server-side exploitation, enabling follow-on malware delivery and broader post-compromise activity. Campaigns in which it appeared involved data theft and extortion operations against organizations running Oracle E-Business Suite, with overlaps to actors using the CL0P extortion brand and links identified to a suspected FIN11 cluster. It was reported as one of the most frequently observed malware families in 2025 incident response investigations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Google Threat Intelligence Group documented that CVE-2025-61882 exploitation combined Server Side Request Forgery (SSRF), Carriage Return Line Feed (CRLF) injection, authentication bypass, and XSL template injection to achieve remote code execution... Known Exploitation Not confirmed Yes (Cl0p/FIN11, CISA KEV).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The GOLDVEIN.JAVA downloader used in EBS attacks is reminiscent of the GOLDVEIN downloader and GOLDTOMB backdoor deployed by UNC5936 during the mass exploitation of the Cleo MFT vulnerability in late 2024.
The GOLDVEIN.JAVA downloader used in EBS attacks is reminiscent of the GOLDVEIN downloader and GOLDTOMB backdoor deployed by UNC5936 during the mass exploitation of the Cleo MFT vulnerability in late 2024.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader/tooling referenced as used in Oracle EBS attacks and linked by researchers to tradecraft associated with suspected FIN11/UNC5936 activity.
A Java-based downloader heavily observed in 2025 investigations and linked in the report to suspected FIN11 activity and CL0P-associated extortion operations.
Malware family dropped as a payload in Oracle EBS exploitation campaigns, likely involved in data exfiltration or further compromise.
Java-based downloader embedded in malicious XSLT templates used against Oracle E-Business Suite; beacons to C2 using traffic disguised as a “TLSv3.1” handshake and returns execution logs embedded in HTML comments. Reported to trace to a PowerShell family seen in prior Cleo campaigns; no follow-on payloads recovered in this reporting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.