GoldenUsbCopy is a custom GoldenJackal malware component used in the group’s newer, largely Go-based toolset deployed from at least May 2022 through March 2024 against government and diplomatic targets, including an unnamed European Union government organization. Its primary role is USB-based collection: it monitors the insertion of USB/removable drives, identifies files of interest on those media, and copies selected files into an encrypted container stored on disk for later exfiltration by other components. Reporting describes GoldenUsbCopy as a file-stealing utility focused on removable media in support of operations against high-value, potentially air-gapped environments. GoldenUsbGo is described as a newer or improved variant/successor of GoldenUsbCopy. The broader GoldenJackal toolchain around it included GoldenAce for USB propagation, GoldenBlacklist/GoldenPyBlacklist for processing email messages of interest, GoldenMailer for exfiltration via Outlook SMTP, and GoldenDrive for exfiltration to Google Drive. The campaigns are associated with GoldenJackal, a cyberespionage actor targeting government and diplomatic entities in Europe, the Middle East, and South Asia, with the apparent objective of stealing confidential information from isolated or sensitive systems. The initial compromise vector for the campaigns involving GoldenUsbCopy is not confirmed in the provided content, though prior GoldenJackal reporting mentioned trojanized software and malicious Word documents as possible entry methods. No specific GoldenUsbCopy-exclusive indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For example, GoldenUsbCopy monitors the insertion of USB drives and copies interesting files to an encrypted container stored on disk...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
In an attack on a European government organization in May 2022, the group used a different custom toolset capable of collecting files from USB drives... For example, GoldenUsbCopy monitors the insertion of USB drives and copies interesting files to an encrypted container stored on disk.
GoldenUsbCopy monitors the insertion of USB drives and copies interesting files to an encrypted container stored on disk, GoldenBlacklist downloads an encrypted archive from a local server and processes email messages contained within, keeping only those of interest.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Monitors removable media and steals files from USB drives (used to exfiltrate/collect data across air-gapped boundaries).
Monitors USB drive insertion and copies selected files into an encrypted local container for later collection or exfiltration.
Monitors USB drives and copies files for later exfiltration as part of the newer Go-heavy toolset used against a European government entity.
A malware tool in GoldenJackal's newer modular set used to steal files from compromised systems and send them to the attackers, likely via USB-mediated workflows.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.