GoldenPyBlacklist is a Python implementation of GoldenBlacklist, an email-processing tool used in the later GoldenJackal toolset observed by ESET in campaigns against government and diplomatic targets, including a national government organization in the European Union between May 2022 and March 2024. It is described as a Python version of the email-scanning tool and is used to process email messages of interest for later exfiltration. This malware is part of GoldenJackal’s broader modular toolset, which was largely written in Go and designed to steal confidential information from high-value, potentially air-gapped systems. In the same toolset, GoldenPyBlacklist operated alongside components such as GoldenUsbCopy/GoldenUsbGo for USB file collection, GoldenAce for USB propagation, GoldenMailer for exfiltration via Outlook SMTP, and GoldenDrive for exfiltration to Google Drive. The activity has been attributed to the GoldenJackal APT group, which has targeted government and diplomatic entities in Europe, the Middle East, and South Asia. The initial compromise vector for the campaigns using this toolset is currently unknown, although prior reporting cited trojanized Skype installers and malicious Word documents as possible GoldenJackal entry points.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"GoldenBlacklist and its Python implementation GoldenPyBlacklist..."
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Python implementation of GoldenBlacklist used for scanning/retaining emails of interest.
Python implementation of GoldenBlacklist used to process email messages of interest for subsequent exfiltration.
PyInstaller-packaged Python variant of GoldenBlacklist with similar decrypt/filter/repack workflow; adds filtering for .msg filenames and uses 7-Zip for archive creation; writes/uses different temp paths and output filename.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.