JackalWorm is a USB-propagating worm used by the GoldenJackal APT in cyberespionage operations targeting government and diplomatic entities, including embassies and government organizations, with the objective of stealing confidential information from high-value and potentially air-gapped systems. It has been observed infecting connected USB drives and propagating other malicious components, most notably delivering the JackalControl trojan/backdoor. Reporting states that GoldenJackal used JackalWorm in an embassy-targeting toolset alongside JackalControl and JackalSteal, and later used a lightweight JackalWorm variant propagated by GoldenAce in a newer modular toolset. The malware is specifically associated with USB-based movement into isolated environments; ESET reported GoldenJackal successfully compromised air-gapped government systems using custom malware spread through removable media. Mentioned behaviors include infecting connected USB drives and use in persistence workflows involving Windows Task Scheduler jobs. High-confidence context links JackalWorm to GoldenJackal activity observed from at least 2019 onward against a South Asian embassy in Belarus and an EU government organization. Initial access for the broader campaigns is unknown, though prior reporting suggested trojanized Skype installers and malicious Microsoft Word documents as possible entry vectors. No standalone IOCs specific to JackalWorm are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Although their use of custom tools spread over USB pen drives, like the 'JackalWorm,' was known, cases of a successful compromise of air-gapped systems were not previously confirmed.
1 distinct technique documented for this family, organized by ATT&CK tactic.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
USB-propagating worm used to infect removable media and facilitate delivery/propagation of other GoldenJackal payloads, including JackalControl; a lightweight version is also referenced as being propagated by GoldenAce.
A custom GoldenJackal tool known for spreading via USB pen drives in espionage operations.
USB-propagation component that disguises itself (e.g., folder icon/renaming) to entice execution and spread other GoldenJackal payloads via removable media; a later lightweight variant is described as limited compared to earlier versions.
Malware used by GoldenJackal APT to establish persistence via Windows Task Scheduler (schtasks.exe).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.