Gold Dragon is a Windows malware family associated with North Korean intrusion activity, including operations attributed to Kimsuky/APT43. It has been observed in espionage-oriented campaigns targeting organizations such as government, research, think tank, business services, manufacturing, and South Korea-linked environments. Gold Dragon has been delivered through dedicated installers and is also associated with document-based infection chains involving Hangul Word Processor content and startup-based execution at user logon.
Gold Dragon performs host reconnaissance by enumerating running processes, checking for anti-malware products and processes, querying persistence-related Registry locations, and collecting the victim username. Collected username information has been used to determine or request additional components from command-and-control infrastructure, indicating a modular architecture. Some variants stage gathered information locally before transmission and encode outbound data with Base64.
The malware establishes persistence on Windows through Startup-folder placement and has also been observed registering itself for autorun. It includes defense-evasion behavior, notably identifying and terminating anti-malware processes. Reporting on later variants indicates use of process hollowing and modularized information-theft functionality, with additional payloads potentially deployed for broader collection or remote control. Gold Dragon has also been observed deleting artifacts after persistence is established, consistent with cleanup and anti-forensics behavior.
Gold Dragon is commonly discussed alongside Ghost419 RAT-related detections and broader North Korea-linked malware clusters, but Gold Dragon itself is best characterized as a modular Windows backdoor used for reconnaissance, persistence, payload retrieval, and protected communication with command-and-control infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Another crowdsourced YARA rule that detected a few of the analyzed samples was one by Florian Roth, which detects the Ghost419 RAT used by the Gold Dragon malware.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Injection method is same as the method used by the original Gold Dragon (behavior of process hollowing on iexplore.exe, svchost.exe,etc.) ... Once cp1093.exe is executed, it copies a normal powershell process (powershell_ise.exe) to the “C:\ProgramData\”path and executes xRAT via process hollowing technique.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Injection method is same as the method used by the original Gold Dragon (behavior of process hollowing on iexplore.exe, svchost.exe,etc.) ... Once cp1093.exe is executed, it copies a normal powershell process (powershell_ise.exe) to the “C:\ProgramData\”path and executes xRAT via process hollowing technique.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information. | Multiple entries explicitly state use of the Windows systeminfo command, e.g., 'BlackEnergy has used Systeminfo to gather the OS version...' and 'OilRig has run hostname and systeminfo on a victim.'
The content repeatedly describes threat actors and malware disabling, stopping, uninstalling, or modifying antivirus, EDR, Windows Defender, AMSI, logging, and other security controls.
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family referenced in connection with Ghost419 RAT within the APT43-related sample set.
Backdoor that collects the victim username and uses it to drive follow-on component downloads from C2.
A malware family used by the attacker via an exclusive installer. It is delivered as a Gzip-compressed payload, decompressed into the %temp% path, executed through rundll32.exe, persists via self-copy and autorun registry registration, uses process hollowing, and appears to support modular payload delivery for additional capabilities.
Kimsuky-linked implant family (active since at least 2017) used for espionage; in this campaign its derivatives provide modular capabilities including system information collection, file exfiltration, credential theft and keylogging, with HTTP-based exfiltration noted as a differentiator versus Brave Prince.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.