GoldenEagle is an Android surveillanceware/trojan family associated in reporting with China-aligned activity targeting the Uyghur ethnic minority. The provided content states it was used in 2015 alongside SilkBean, DoubleAgent, and CarbonSteal in operations attributed to APT15, and separately notes targeting alignment with other Android trojans used by GREF. Lookout also connected infrastructure used by GoldenEagle to the Chinese defense contractor Xi’an Tianhe Defense Technology. Documented capabilities include collecting SMS messages, call logs, and contact lists; sending messages to an attacker-controlled number; checking whether the device is rooted; retrieving files from external storage including .doc, .txt, .gif, .apk, .jpg, .png, .mp3, and .db files; and taking photos with the device camera. For command and control and exfiltration, GoldenEagle uses HTTP POST requests and has exfiltrated data via both HTTP and SMTP. High-confidence behavioral indicators from the content therefore include theft of SMS, call logs, contacts, external-storage files of the listed extensions, camera capture, root-status checks, and HTTP/SMTP-based data exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This aligns with the targeting of other Android trojans previously used by GREF (BadBazaar, SilkBean, DoubleAgent, CarbonSteal, and GoldenEagle).
4 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
GoldenEagle is an Android surveillanceware used by APT15 for espionage against targeted individuals.
Surveillanceware family discussed in relation to shared/adjacent infrastructure with DoubleAgent activity and links inferred from insecure C2/admin-panel artifacts.
Trojan referenced as another malware family previously used by GREF in related targeting activity.
Android malware observed taking photos with the device camera.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.