GoldenSpy is a Windows backdoor malware family covertly deployed through Chinese VAT and tax-management software associated with the Golden Tax ecosystem, most notably Aisino Intelligent Tax. It is characterized as a supply-chain-delivered implant that is installed silently after the legitimate software is deployed, including delayed installation behavior observed roughly two hours after setup. GoldenSpy establishes persistence as autostart services and has been reported to maintain redundant service-based execution, including respawning behavior if one component is removed. It can survive removal of the associated tax software and includes self-protection and cleanup functionality, including deletion of files, folders, registry artifacts, and self-removal components used after public exposure.
Functionally, GoldenSpy provides remote backdoor access with high privileges on infected Windows systems. Reported capabilities include execution of remote commands through the Windows command shell, upload and execution of arbitrary binaries, creation of new local user accounts, and exfiltration of host environment information over its command-and-control channel. Network communications have been observed over multiple non-standard ports, with randomized beacon timing used to reduce detection. Public reporting also describes repeated operator attempts to uninstall or erase the malware from victim environments after disclosure, using increasingly evasive methods.
GoldenSpy has been linked to trojanized, digitally signed tax software distributed to organizations operating in China, making it notable as a software supply-chain intrusion risk rather than a conventional phishing-delivered threat. Victims and at-risk organizations include foreign enterprises required to use mandated tax software, with reporting highlighting sectors such as pharmaceutical, healthcare, chemical, finance, and other multinational businesses with operations in China. Publicly available reporting has described the malware as enabling unfettered access and potential follow-on deployment of additional payloads, but attribution to a specific threat actor and confirmed operational exploitation objectives remain publicly unresolved.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Si l’ajout d’une fonctionnalité assimilable à une porte dérobée peut être le fait de son éditeur, celui-ci peut également être victime d’une attaque sur la chaîne d’approvisionnement visant à compromettre ses clients via ses logiciels.
Aisino Version: Numerous, published software versions with a trojanized file within the tax software. The tax software and the loaders for the malware were digitally signed. Baiwang Version: Numerous, published software versions were distributed that contain malicious components.
They have persistence mechanisms, communicate with a remote server at a random frequency, and allow arbitrary code to be executed with system administrator privileges without user interaction. | the installation of China’s Aisino Intelligent Tax VAT management software led to the deployment of what appears to be a backdoor dubbed “GoldenSpy” by Trustwave.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
Execution User Execution: Malicious File (T1204.002) Aisino Version: See T1195.002 (above) Baiwang Version: See T1195.002 (above)
Persistence Create or Modify System Process: Windows Service (T1543.003) Aisino Version: See T1569.002 (above) Baiwang Version: See T1569.002 (above)
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Ce code a pour effet de désinstaller GoldenSpy et d’effacer toutes les traces de sa présence sur la machine.
Baiwang Version: Files were timestamped with randomly generated "Creation" and "Last write". | Aisino Version: Numerous GoldenSpy uninstallers deployed to remove "svm.exe" files and directories after 25 June report. Baiwang Version: INF functions execute and delete upon completion.
Baiwang Version: The malware checks if the victim system is running 64-bit version of Windows 7 or above before continuing the process.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Aisino Version: Numerous IP/domains are coded for the malware to communicate. Baiwang Version: Numerous IP/domains are coded for the malware to download its additional files.
it also installed a hidden backdoor on the system that enabled a remote adversary to execute Windows commands or to upload and execute any binary ... connected to a command and control server completely separate from the tax software’s network infrastructure. | After the first three attempts to contact its command and control server, it randomizes beacon times. This is a known method to avoid network security technologies designed to identify beaconing malware.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that uses legitimate-looking system paths for installation and concealment.
Malware that exfiltrates host environment information to an external C2 domain.
Malware that executes remote commands in the Windows shell using WinExec.
Backdoor malware with an uninstaller that removes registry entries, files, folders, and itself.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.