JackalScreenWatcher is a malware implant associated with the GoldenJackal APT group. Kaspersky reported it as part of GoldenJackal’s toolset and assessed that it has likely been in use since 2020. The malware was observed in campaigns targeting high-profile entities in the Middle East and South Asia, including government entities in Iran, and GoldenJackal more broadly has targeted government and diplomatic organizations in Europe, the Middle East, and South Asia. Based on the provided reporting, JackalScreenWatcher is used alongside other GoldenJackal implants such as JackalPerInfo and is intended for collection activity on compromised hosts, specifically gathering screenshots and various files from an infected system. Kaspersky publicly documented JackalScreenWatcher together with other GoldenJackal implants including JackalControl, JackalSteal, JackalWorm, and JackalPerInfo. Initial access for GoldenJackal operations has been reported elsewhere in the provided content as involving trojanized software and malicious documents, but the specific infection vector for JackalScreenWatcher itself is not stated. No specific indicators of compromise unique to JackalScreenWatcher are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The group’s known toolset includes several implants written in C#: ... JackalScreenWatcher"
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C# espionage implant in GoldenJackal’s known toolset; specific functionality not described in the provided content.
GoldenJackal post-exploitation component used to capture screenshots and collect files from compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.