JackalPerInfo is a malware implant associated with the GoldenJackal APT group. Kaspersky reported it as part of GoldenJackal’s known toolset alongside JackalControl, JackalSteal, JackalWorm, and JackalScreenWatcher, and linked new JackalPerInfo samples to GoldenJackal, assessing that the malware has likely been in the group’s toolset since 2020. The malware was described as being used in the post-exploitation stage. GoldenJackal is a cyber-espionage actor discovered in 2020 that targets high-profile entities in the Middle East and South Asia, and later reporting describes GoldenJackal activity since at least 2019 against government and diplomatic entities in Europe, the Middle East, and South Asia, including operations targeting air-gapped systems. Kaspersky obtained JackalControl C2 communications from a campaign targeting government entities in Iran active until early April 2023, providing contextual evidence of GoldenJackal operations in that sector. The provided content does not describe JackalPerInfo’s specific functionality, infection vector, persistence, or standalone indicators of compromise beyond its association with GoldenJackal and its use during post-exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The group’s known toolset includes several implants written in C#: JackalControl, JackalSteal, JackalWorm, JackalPerInfo, and JackalScreenWatcher"
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C# espionage implant in GoldenJackal’s known toolset; specific functionality not described in the provided content.
GoldenJackal post-exploitation component used to collect information/files from infected hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.