GoldenMailer is a GoldenJackal exfiltration component used in the group’s newer modular toolset deployed against government and diplomatic targets, including an unnamed European Union government organization targeted between May 2022 and March 2024. It is described as a Python/PyInstaller malware whose role is to exfiltrate stolen files by sending emails with attachments to attacker-controlled accounts. Reported SMTP infrastructure includes smtp-mail.outlook.com and smtp.office365.com over SMTP/STARTTLS on port 587, and observed attacker-controlled Outlook accounts include mariaalpane@outlook[.]com, katemarien087@outlook[.]com, and spanosmitsotakis@outlook[.]com. GoldenMailer operated alongside other GoldenJackal tools in a broader air-gap-focused espionage toolchain that used USB-based propagation and collection utilities, email-processing components, and Google Drive exfiltration. High-confidence reporting links GoldenJackal activity to government and diplomatic organizations in Europe, the Middle East, and South Asia, with the overall objective assessed as theft of confidential information from high-value, potentially air-gapped systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...and GoldenMailer exfiltrates files by sending emails with attachments to attacker-controlled accounts.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exfiltrates stolen files by emailing them as attachments to attacker-controlled mailboxes.
A malware component used to exfiltrate stolen information by sending it to the attackers via email.
Exfiltrates stolen data by sending it to attacker-controlled email destinations.
Exfiltrates files by emailing them as attachments to attacker-controlled accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.