GoldenAce is a GoldenJackal malware component used as a USB-based distribution and propagation utility in the group’s newer toolset observed from May 2022 to March 2024. It is described as the malware used for USB infection and as a tool that propagates other malicious executables, including a lightweight version of JackalWorm, to other systems via USB drives. It also retrieves staged files from USB media. ESET linked this toolset to attacks against a European government organization, and GoldenJackal overall has targeted government and diplomatic entities, including air-gapped or potentially air-gapped high-value systems. In the same toolset, GoldenAce operated alongside GoldenUsbCopy and GoldenUsbGo, which monitored USB drives and stole files for exfiltration, as well as other collection and exfiltration components such as GoldenBlacklist, GoldenPyBlacklist, GoldenMailer, and GoldenDrive. The initial compromise vector for the campaigns described by ESET is unknown, although prior reporting cited trojanized software and malicious documents as possible GoldenJackal entry points. No GoldenAce-specific indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The new malware used for USB infection is named GoldenAce, and the tools that steal files and send them to the attackers are named 'GoldenUsbCopy' and 'GoldenUsbGo,' with the latter being a more recent variant of the former.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
USB-based distribution/propagation utility used to move executables and retrieve files via removable media.
Propagation component that spreads GoldenJackal malware (including a lightweight JackalWorm) to additional systems via USB drives, not limited to air-gapped hosts.
A Go-based malware component in GoldenJackal's newer modular toolset used to infect USB drives and support movement of malicious tooling into isolated environments.
USB-based propagation/distribution tool that creates hidden directories on removable drives, drops a payload ('update') and a disguised launcher (lightweight JackalWorm as 'upgrade' renamed to a hidden-folder name), and retrieves staged files from the USB 'trash' directory to a local staging path.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.