GoldenHowl is a modular Python backdoor used by the GoldenJackal cyberespionage group in operations against government and diplomatic targets, including a South Asian embassy in Belarus in 2019. It was delivered to air-gapped systems via compromised USB drives by the GoldenDealer malware, alongside the GoldenRobo file stealer. GoldenHowl is described as a multi-functional backdoor with modules for file theft and exfiltration, file upload/download, file listing, writing files, persistence, SSH command execution, IP and port scanning, SSH tunneling, and SOCKS proxying. Persistence is achieved via a scheduled task named Microsoft\Windows\Multimedia\SystemSoundsService2. ESET reported that GoldenHowl was distributed as a self-extracting archive containing legitimate Python 2.7.15 binaries renamed as WinAeroModule.exe together with malicious scripts, and that it decrypts configuration data using Fernet with the hardcoded key _ylmUTbqcx6FxMZ5ZvNxDQZYuNh41yxhKcPJLzxgqEY=. Its transport_http module communicated over HTTPS with command-and-control infrastructure observed at 83.24.9[.]124 on port 443 using URLs of the form https://<server_address>:<server_port>/<client_id>/. ESET also noted the term transport_http overlaps with terminology seen in Turla- and MoustachedBouncer-linked tooling, but treated that only as a low-confidence attribution clue. GoldenHowl formed part of GoldenJackal’s older USB-based air-gap bridging toolset, whose apparent objective was theft of confidential information from high-value, potentially isolated systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During the attack on a South Asian embassy in Belarus in August 2019, the hackers used several custom tools, including GoldenDealer malware to deliver executables to the air-gapped system via USB monitoring, the GoldenHowl backdoor...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular backdoor deployed onto air-gapped systems via USB as part of GoldenJackal’s toolchain.
Custom backdoor used in GoldenJackal operations against air-gapped government and diplomatic targets.
Modular backdoor used for persistence and remote operations, including file theft, task scheduling, file transfer with C2, and SSH tunneling.
A multi-functional Python backdoor used in GoldenJackal intrusions to steal files, maintain persistence, scan for vulnerabilities, and communicate with command-and-control infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.