JackalSteal is a malware component used by the GoldenJackal APT group. It is described as a file collector and exfiltrator and was part of GoldenJackal’s earlier embassy-targeting toolset alongside JackalControl and JackalWorm. Reporting links this toolset to cyberespionage operations against embassies and government organizations, including government entities in Iran and a South Asian embassy in Belarus, with GoldenJackal broadly targeting high-profile entities in the Middle East, South Asia, and Europe since at least 2019. GoldenJackal’s apparent objective is theft of confidential information, including from high-value or potentially air-gapped systems. JackalSteal was observed as one of multiple bespoke malware families in GoldenJackal’s arsenal, but the provided content does not include further technical details, specific infection vectors, or distinct indicators of compromise for JackalSteal itself. Initial access for GoldenJackal activity is assessed as unknown, though prior reporting suggested trojanized Skype installers and malicious Microsoft Word documents as possible entry vectors for the broader intrusion set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"In various attacks... we observed the following tools in GoldenJackal’s arsenal: JackalControl, JackalSteal, a file collector and exfiltrator..."
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a distinct GoldenJackal malware family used in the embassy intrusion; specific functionality not described in the provided content.
File collection and exfiltration implant used for espionage; later versions accept C2 servers as arguments rather than hardcoding URLs.
Data-stealing component used by GoldenJackal; configured/deployed via JackalControl and focused on collecting files of interest.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.