Security agencies and researchers warned that GoldenSpy was covertly installed alongside tax software from Aisino and other government-authorized providers used by foreign companies operating in China. Trustwave reported that the malware was delivered with Aisino Intelligent Tax software and acted as a stealthy backdoor with SYSTEM-level privileges, enabling remote command execution, arbitrary file upload and execution, persistence through multiple autostart services, and silent reinstallation even after the tax application was removed. ANSSI said several French companies in China detected the malware, while the FBI said at least two Western companies identified malicious activity tied to updates from Aisino and Baiwang.
Authorities said the software created a potential supply-chain intrusion path into corporate networks, particularly for organizations in pharmaceutical, healthcare, chemical, and financial sectors. The FBI assessed the malware likely supported prepositioning for remote code execution and data exfiltration, and ANSSI linked the case to broader concerns over mandatory local business software such as GoldenHelper and Beijing One Pass, which also showed spyware or backdoor-like behavior. Although ANSSI noted there was no public proof that the hidden access had been operationally exploited, agencies in France, Germany, and the United States urged companies to isolate the tax software in dedicated environments, restrict privileges, segment networks, monitor logs and outbound traffic, and hunt for indicators of compromise.

Trace attribution and downstream blast radius.
19 events from the most recent confirmed update back to the earliest known activity.
On December 7, 2022, ANSSI published a report warning that some mandatory business software, including Chinese tax and benefits software, could contain hidden backdoor-like functionality. The report highlighted GoldenSpy, GoldenHelper, and Beijing One Pass and recommended isolation, filtering, logging, and least-privilege controls.
On 2022-11-23, ANSSI published the notice "Illustration des problématiques liées à l’intégration de logiciels non maitrisés – Le cas de GoldenSpy," using GoldenSpy, GoldenHelper, and Beijing One Pass to illustrate the risks of mandated or low-trust software. The notice said some affected versions dated back to 2018, noted French companies in China had reported detections and alerts in 2022, and stated no public information had confirmed exploitation of the access as of the report date.
ANSSI said French companies established in China reported in 2022 that installation of mandatory software triggered multiple alerts from their security solutions. The report also stated that several French companies operating in China detected GoldenSpy in their information systems.
Recorded Future published a report in July 2021 stating that Beijing One Pass software exhibited features that could be used as a backdoor. ANSSI later cited this case alongside GoldenTax as another example of mandatory software posing embedded access risks.
On 2020-08-24, the FBI and CISA issued FLASH alert AC-000131-MW describing additional tactics, techniques, procedures, and indicators tied to malware embedded in Aisino and Baiwang tax software associated with China's Golden Tax System. The alert said operators repeatedly tried to remove GoldenSpy from victim networks using increasingly evasive methods after disclosure and warned that organizations doing business in China remained at risk from the software supply chain.
On 21 August 2020, Germany's BKA published a warning notice about possible cyber espionage involving the GOLDENSPY malware. The notice identified GOLDENSPY as the malware of concern but provided minimal additional technical detail in the referenced content.
The FBI issued Alert Number AC-000129-TT on 23 July 2020 warning that Chinese government-mandated tax software used by foreign companies contained malware enabling hidden backdoor access. The alert linked the activity to Baiwang and Aisino software and included indicators of compromise and mitigation guidance.
From July 1, 2020, a new version of the GoldenSpy uninstallation code was distributed with changes that appeared designed to evade Trustwave's published YARA rule. This followed the earlier silent removal of GoldenSpy after public exposure.
On June 28, 2020, after Trustwave's reporting was widely publicized, Aisino Intelligent Tax software silently downloaded code that uninstalled GoldenSpy and erased traces of its presence. ANSSI cited this as evidence of post-exposure cleanup behavior.
On June 25, 2020, Trustwave published a report stating that installation of Aisino Intelligent Tax VAT management software deployed an apparent hidden backdoor dubbed GoldenSpy. The report said GoldenSpy silently installed about two hours after the tax software, established persistence, contacted remote servers, and enabled arbitrary code execution with administrator privileges.
Trustwave SpiderLabs said its Threat Fusion Team identified the GoldenSpy activity during a threat hunt in April 2020 at a customer that had recently opened offices in China. Trustwave assessed the current GoldenSpy campaign began in April 2020.
ANSSI's report, citing Trustwave, said the GoldenHelper code family was active through July 2019. It was tied to Golden Tax Invoicing software (Baiwang Edition).
The FBI reported that in April 2019, employees of a US pharmaceutical company discovered malware in Baiwang software that created a backdoor on the company's network. The alert assessed that such malware likely enabled remote code execution and data exfiltration prepositioning.
The FBI stated that since at least March 2019, Baiwang software updates automatically installed a driver alongside the main tax program. The same alert said at least two Western companies operating in China had detected malware delivered through tax software upgrades as early as March 2019.
The FBI said that in July 2018, an employee of a US pharmaceutical company with business interests in China downloaded Baiwang Tax Control Invoicing software from baiwang.com. This software was part of the government-authorized VAT ecosystem.
ANSSI stated that the first affected versions of the Chinese mandatory software discussed in its report were released in 2018. This covered software such as GoldenTax and Beijing One Pass that reportedly included hidden backdoor-like features.
Trustwave documented a separate suspicious code family, GoldenHelper, as active from January 2018 and integrated into Golden Tax Invoicing software (Baiwang Edition). It downloaded and executed payloads with administrator privileges using a UAC bypass.
Trustwave noted that Chenkuo Technology announced a "big data cooperation" partnership with Aisino in October 2016. Trustwave highlighted this as occurring two months before the earliest identified GoldenSpy variant.
Trustwave said related GoldenSpy variants were identifiable as early as December 2016, predating the 2020 campaign it investigated. The FBI alert also stated GoldenSpy was believed to have existed since 2016.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
6 references tracked. Mallory keeps watching after this page renders.
bka.de
Open sourcetrustwave.com
Open sourcecert.ssi.gouv.fr
Open sourceic3.gov
Open sourceic3.gov
Open sourcecert.ssi.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.