GOLDMAX

GOLDMAXGoldMax

Description

Written in Go, GoldMax acts as command-and-control backdoor for the actor. It uses several different techniques to obfuscate its actions and evade detection. The malware writes an encrypted configuration file to disk, where the file name and AES-256 cipher keys are unique per implant and based on environmental variables and information about the network where it is running. GoldMax establishes a secure session key with its C2 and uses that key to securely communicate with the C2, preventing non-GoldMax-initiated connections from receiving and identifying malicious traffic. The C2 can send commands to be launched for various operations, including native OS commands, via psuedo-randomly generated cookies. The hardcoded cookies are unique to each implant, appearing to be random strings but mapping to victims and operations on the actor side.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
GoldFinder
Software
Iron Backdoor
Software
GOLDDROP
Actor
GoldenJackal
Software
SpicyOmelette
Software
Golden Axe
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.