GoldenUsbGo is a Go-based file theft and exfiltration utility used by the GoldenJackal APT in campaigns targeting government and diplomatic organizations, including an EU government entity. It is described as an improved and more recent successor to GoldenUsbCopy and was part of GoldenJackal’s newer modular toolset deployed from at least May 2022 to March 2024, including operations against high-value and potentially air-gapped systems.
Its primary role is to monitor USB drives and copy files for exfiltration. In the newer GoldenJackal toolchain, USB propagation was handled by GoldenAce, while GoldenUsbCopy and GoldenUsbGo collected files from removable media for later theft. GoldenUsbGo no longer uses AES-encrypted configuration; instead, it exfiltrates files according to hardcoded instructions. Reported targeting logic includes selecting files modified within up to 14 days, smaller than 20 MB, and matching keywords such as "pass," "login," or "key," or extensions such as .pdf, .doc, .docx, .sh, and .bat.
GoldenUsbGo is associated with GoldenJackal’s broader espionage activity focused on stealing confidential information from government and diplomatic victims in Europe, the Middle East, and South Asia. Related malware in the same ecosystem includes GoldenAce for USB infection/propagation, GoldenBlacklist and GoldenPyBlacklist for processing email messages of interest, GoldenMailer for exfiltration via Outlook SMTP, and GoldenDrive for exfiltration to Google Drive. The initial compromise vector for the campaigns using this malware is not confirmed in the provided content, though prior reporting cited trojanized Skype installers, malicious Word documents, and remote-template-injection/Follina chains as possible GoldenJackal entry methods.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The new malware used for USB infection is named GoldenAce, and the tools that steal files and send them to the attackers are named 'GoldenUsbCopy' and 'GoldenUsbGo,' with the latter being a more recent variant of the former. GoldenUsbGo no longer uses AES-encrypted configuration but instead exfiltrates files based on hardcoded instructions.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newer Go-based variant/functionally similar successor to GoldenUsbCopy for monitoring USB devices and stealing files.
Improved successor to GoldenUsbCopy; monitors USB drives and copies files for exfiltration in GoldenJackal’s newer toolchain.
A more recent variant of GoldenUsbCopy that exfiltrates files according to hardcoded rules, including recently modified files under 20 MB matching specific keywords or file types.
Simplified/tailored successor to GoldenUsbCopy: periodically checks a small set of drive letters, selects files via hardcoded criteria (keywords, size, recency, extensions), gzip-compresses and AES-CFB encrypts file contents/filenames into a hardcoded container path; maintains processed-file state in memory only.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.