GoldenRobo is a custom file collection and data exfiltration malware used by the GoldenJackal cyberespionage group in attacks against government and diplomatic targets, including a South Asian embassy in Belarus in 2019. It was deployed as part of GoldenJackal’s older air-gap-focused toolset alongside GoldenDealer, which staged payloads on USB drives and delivered them to isolated systems, and GoldenHowl, a modular backdoor. Once an infected USB drive was inserted into an air-gapped machine, GoldenDealer installed GoldenRobo on the isolated host.
GoldenRobo is described as a simple Go-written component and a file stealer/file collector. It uses the legitimate Windows Robocopy utility to stage files for exfiltration. It scans drives A: through Z: for recently accessible files and targets documents, images, certificates, encryption keys, archives, and OpenVPN configuration files, including extensions such as .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .rtf, .tif, .jpg, .jpeg, .crt, .key, .p12, .ovpn, .zip, and .rar. In the USB-mediated workflow described by ESET, GoldenRobo stores collected data in a hidden directory on the USB drive so it can later be transferred back to an internet-connected system. ESET also reported that GoldenRobo archives staged files into a ZIP file named in the format _1423-da77-fe86<month>-<day> and exfiltrates the archive base64-encoded to https://83.24.9[.]124/8102/. ESET stated the hardcoded URL suggests the sample was compiled specifically for that victim.
High-confidence associations in the reporting tie GoldenRobo to GoldenJackal operations targeting confidential information on high-value, potentially air-gapped systems in government and diplomatic environments. A reported network indicator associated with GoldenRobo exfiltration is 83.24.9[.]124.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During the attack on a South Asian embassy in Belarus in August 2019, the hackers used several custom tools, including GoldenDealer malware to deliver executables to the air-gapped system via USB monitoring, the GoldenHowl backdoor and GoldenRobo, a file collector and exfiltrator.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
File-stealing payload delivered to air-gapped systems via USB in GoldenJackal intrusions.
Custom tool used to collect files and exfiltrate data from compromised systems.
Go-based collection/exfiltration tool executed on an internet-connected PC; uses Windows robocopy to copy files (including from USB media) and transmits them to an attacker-controlled server.
A file-stealing malware component that searches compromised air-gapped systems for sensitive files such as documents, images, certificates, encryption keys, archives, and OpenVPN configuration files, then stores them on a USB drive for later exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.