GoldenDealer is a custom GoldenJackal malware component used to bridge air-gapped environments via removable media. It was observed in attacks against government and diplomatic targets, including a South Asian embassy in Belarus in 2019, and is associated with the GoldenJackal cyberespionage group, which has targeted government and diplomatic entities in Europe, the Middle East, and South Asia since at least 2019. GoldenDealer is deployed on internet-connected systems, where it monitors for USB drive insertion, copies itself and other malicious components to removable media, and can download executables from command-and-control infrastructure and hide them on the USB device. When the compromised USB drive is inserted into an air-gapped machine, GoldenDealer retrieves additional malware from the drive and executes it, including GoldenHowl, a modular backdoor, and GoldenRobo, a file collection and exfiltration tool. In the documented workflow, GoldenRobo collects documents, images, certificates, encryption keys, archives, and OpenVPN configuration files from the isolated host, stores them in a hidden directory on the USB drive, and the data is later exfiltrated when the drive is reconnected to an online system running GoldenDealer. High-confidence behaviors reported by ESET include monitoring removable drive insertion and internet connectivity, staging base64-encoded executables from C2 for USB transfer, and using USB-mediated delivery to compromise isolated systems. GoldenDealer attempts persistence by creating a Windows service named NetDnsActivatorSharing and falls back to a Run registry key if service creation fails. It also modifies HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden to keep hidden files from being shown in Windows Explorer. Reported working-directory artifacts include XOR-encrypted JSON configuration data and files named b8b9-de4d-3b06-9d44, fb43-138c-2eb0-c651, and 130d-1154-30ce-be1e, observed under C:\Windows\TAPI. It checks connectivity by issuing periodic GET requests to https://1.1.1.1/<user_id> and expecting a 404 response, and reported 2019 C2 infrastructure includes 83.24.9[.]124 as primary and 196.29.32[.]210 as secondary.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During the attack on a South Asian embassy in Belarus in August 2019, the hackers used several custom tools, including GoldenDealer malware to deliver executables to the air-gapped system via USB monitoring...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
GoldenDealer monitors for the insertion of USB drives on those systems, and when it happens, it automatically copies itself and other malicious components onto it. | Eventually, that same USB drive is inserted into an air-gapped computer, allowing GoldenDealer to install GoldenHowl (a backdoor) and GoldenRobo (a file stealer) onto these isolated systems.
GoldenDealer monitors for the insertion of USB drives on those systems, and when it happens, it automatically copies itself and other malicious components onto it. | Eventually, that same USB drive is inserted into an air-gapped computer, allowing GoldenDealer to install GoldenHowl (a backdoor) and GoldenRobo (a file stealer) onto these isolated systems.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
USB-monitoring/propagation component used to bridge air-gapped environments: stages payloads onto removable media from C2-connected hosts and triggers execution on air-gapped hosts when the USB is inserted.
Custom malware used to deliver executables to air-gapped systems via USB monitoring.
Staging/delivery component on an internet-connected host that infects USB drives, exchanges host info with an external server, receives appropriate payloads, copies them to USB, and ultimately enables execution on the air-gapped system when the USB is re-inserted.
A malware component used on internet-connected systems to monitor for USB insertion, copy itself and other malicious components to removable media, and later exfiltrate stolen data from air-gapped systems to the attackers' C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.