Golden Goose Trojan is an underground-advertised malware loader described as a sophisticated tool for stealthy operations and persistence. According to the reported forum listing, it supports customized pinning via vulnerable user applications, executes DLLs directly in memory to evade antivirus detection by avoiding disk writes, and uses a private encrypted command-and-control protocol based on Diffie-Hellman key exchange. The advertised administration panel was described as being built with AngularJS and Bootstrap and allegedly allows operators to list infected bots, terminate processes, upload and download files, and execute arbitrary code. The malware was reportedly offered on a subscription basis for approximately $700 per month. The available content attributes this information to a SOCRadar observation of a dark web/underground forum sales post; no specific threat actor, victim sector, infection vector beyond the claimed loader functionality, or concrete indicators of compromise were provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Golden Goose Trojan is a newly advertised malware loader designed for stealthy operations and persistence. It features customized pinning via vulnerable user applications, in-memory DLL execution to evade antivirus detection, and uses a private encrypted protocol based on Diffie-Hellman for secure C2 communication. It includes a modern admin panel for bot management and remote code execution.
Golden Goose Trojan is a newly advertised malware loader designed for stealthy operations and persistence. It features customized pinning via vulnerable user applications, in-memory DLL execution to evade antivirus detection, and uses a private encrypted protocol based on Diffie-Hellman for secure C2 communication. It includes a modern admin panel for bot management and remote code execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.