JackalControl is a trojan/backdoor associated with the GoldenJackal APT group. It is part of GoldenJackal’s embassy-targeting toolset, alongside JackalSteal and JackalWorm, and has been observed in campaigns targeting government and diplomatic entities, including government entities in Iran and a South Asian embassy in Belarus. ESET reported that JackalWorm infects connected USB drives and delivers JackalControl, indicating a USB-based propagation and air-gap bridging workflow. ESET also observed GoldenJackal executing PowerShell scripts in September 2019 to download the JackalControl backdoor. Kaspersky reported obtaining JackalControl command-and-control communications from a campaign targeting government entities in Iran that remained active until early April 2023. The malware is linked to GoldenJackal operations focused on stealing confidential information from high-value and potentially air-gapped systems. Initial compromise for GoldenJackal activity is not confirmed, though Kaspersky previously suggested trojanized Skype installers and malicious Microsoft Word documents as possible entry vectors for the broader intrusion set. High-confidence indicators directly tied in the content to JackalControl are limited to its role in GoldenJackal’s toolset, its delivery via infected USB drives by JackalWorm, its use in government-focused campaigns, and the existence of observed C2 communications in the Iran-targeting activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...infecting connected USB drives and delivering a trojan dubbed JackalControl."
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan delivered via infected USB drives as part of GoldenJackal’s toolset for compromising segmented/air-gapped environments.
C# backdoor used for espionage; observed being downloaded via PowerShell and then used to execute additional PowerShell scripts and to download/run legitimate tools (e.g., Plink, PsExec).
C2 communications/framework used in a campaign against Iranian government entities; used for victim profiling and to deploy/configure follow-on components (e.g., JackalSteal).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.