GoldenDrive is a GoldenJackal data-exfiltration component used in the group’s newer modular toolset deployed from at least May 2022 through March 2024 against government and diplomatic targets, including a European government organization. Its specific role is to exfiltrate stolen information by uploading files to Google Drive, in contrast to GoldenMailer, which sends data via email. ESET reported that this later GoldenJackal toolset was largely written in Go and was part of a broader framework designed to steal confidential information from high-value and potentially air-gapped systems. The wider intrusion set relied heavily on USB-based propagation and collection, with related components including GoldenAce for USB propagation, GoldenUsbCopy and GoldenUsbGo for file theft from removable media, and GoldenBlacklist/GoldenPyBlacklist for processing email messages of interest prior to exfiltration. Initial compromise for GoldenJackal activity is not confirmed in ESET’s telemetry, though Kaspersky previously reported possible entry vectors including trojanized Skype installers, malicious Word documents, and remote template injection leading to Follina exploitation. A specific operational detail reported for GoldenDrive is that it uploads files to Google Drive using hardcoded credentials.json and token.json files. The malware is associated with GoldenJackal, an espionage-focused threat actor active since at least 2019 and known for targeting government and diplomatic entities in Europe, the Middle East, South Asia, and a South Asian embassy in Belarus.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Finally, there's GoldenMailer, which emails the stolen information to the attackers, and GoldenDrive, which uploads the data to Google Drive.
1 distinct technique documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exfiltrates stolen data by uploading it to attacker-controlled Google Drive storage.
A malware component used to exfiltrate stolen data by uploading it to Google Drive.
Exfiltrates stolen information by uploading it to Google Drive.
Go-based exfiltration utility that uploads a specified file to attacker-controlled Google Drive using hardcoded OAuth credential/token files; uploads one file per execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.