GoldFinder is a Go-based malware tool associated with NOBELIUM, also tracked as APT29, Cozy Bear, and Midnight Blizzard, and was used during post-compromise activity linked to the SolarWinds intrusion. It appears to have served as a custom HTTP tracing and logging utility rather than a conventional full-featured implant. Its primary purpose was to determine how outbound HTTP traffic from a compromised host reached a predefined command-and-control endpoint, helping the operator identify internet connectivity, HTTP proxy servers, redirectors, and other intermediary network devices in the path.
GoldFinder performed HTTP GET requests and recursively followed redirects until a successful response was received, reportedly supporting long redirect chains. It logged route and hop information along with HTTP response metadata such as status codes, headers, and returned content. This behavior indicates a reconnaissance role focused on mapping egress paths and understanding where malicious traffic might be inspected, redirected, or logged inside victim environments or along external infrastructure.
The malware has been described as a backdoor in some reporting, but the strongest supported characterization is a specialized reconnaissance utility used in support of command-and-control operations. It was one of several malware families deployed by NOBELIUM in layered post-exploitation activity alongside tools such as SUNBURST, TEARDROP, GoldMax, and Sibot. GoldFinder was observed in compromised customer networks in 2020 and is closely tied to the actor’s espionage operations against high-value targets, including government and related sectors affected by the SolarWinds campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom HTTP tracer utility used to map network paths to command-and-control infrastructure and log responses locally.
APT29 tool used for network path and proxy discovery by issuing HTTP GET requests to identify internet connectivity and redirectors.
Backdoor implant referenced as one of the malware families involved in the SolarWinds attack attributed to NOBELIUM.
Referenced only in a citation title as malware/tooling associated with NOBELIUM.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.