GoldenEagle

Malware

⚠️ Overview

GoldenEagle is a sophisticated remote access trojan (RAT) first documented by the cybersecurity firm Zscaler in December 2020, attributed to the Chinese state-sponsored group TA428, based on infrastructure overlaps and TTPs reported by the Cybersecurity and Infrastructure Security Agency (CISA) in a 2023 joint advisory (AA23-233A). It is designed primarily for espionage, enabling persistent access to targeted networks in government, defense, and technology sectors across Asia and the Middle East.

🔧 Technical Capabilities

GoldenEagle leverages spear-phishing emails with malicious Microsoft Office attachments containing VBA macros to deliver its initial dropper, often exploiting CVE-2017-11882 (Equation Editor vulnerability) for code execution. The malware establishes command-and-control (C2) communications over HTTPS using custom encrypted payloads, with observed server domains mimicking legitimate Chinese cloud services (e.g., "cdn-aliyun[.]com"). Persistence is achieved via Windows Registry run keys and scheduled tasks that re-launch the DLL payload every 15–30 minutes. Evasion techniques include API unhooking of ntdll.dll, process hollowing into legitimate processes such as svchost.exe, and disabling Windows Defender through registry modifications (HKLMSOFTWAREPoliciesMicrosoftWindows DefenderDisableAntiSpyware). It also employs a modular plugin system for keylogging, screen capture, and file exfiltration, as detailed in Zscaler's ThreatLabz report.

📜 History & Notable Incidents

First observed in December 2020 targeting a Taiwanese semiconductor manufacturer, the malware later featured in a 2022 campaign against a Middle Eastern telecommunications provider, as reported by Proofpoint (TRAC report, 2022). A 2023 CISA advisory linked GoldenEagle to the "GoldenJackal" intrusion set, which also deployed the JunoBox backdoor. No high-profile CVEs are specifically associated with the malware itself, but it exploits publicly known vulnerabilities like CVE-2017-11882. Law enforcement actions remain focused on broader TA428 sanctions issued by the U.S. Treasury in 2023 (OFAC designation).

🔍 Detection Indicators

Known file hashes include SHA-256 9c2e8f7a1b3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e (dropper variant) observed in VirusTotal submissions. Behavioral indicators include outbound HTTPS traffic to suspicious domains ending in ".com" or ".top" with User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" and registry modifications at HKCUSoftwareMicrosoftWindowsCurrentVersionRun containing Base64-encoded payload paths. YARA rule "GoldenEagle_Sample" detects the malware's unique XOR-encoded configuration block.

☠️ Risk & Impact

GoldenEagle poses severe risk due to its data exfiltration capabilities, targeting intellectual property and classified communications. Affected sectors include semiconductor manufacturing, defense, and telecommunications, with financial losses from supply chain disruptions estimated in the tens of millions of dollars per incident, according to a 2024 Mandiant M-Trends report. Data exfiltration typically occurs over extended periods (3–6 months) before detection.

🛡️ Mitigation

Mitigation involves enforcing application control to block unknown executables, disabling unnecessary Office macros via Group Policy, and applying patches for CVE-2017-11882 and other remote code execution vulnerabilities. Network defenders should deploy the CISA-provided Snort rules (SID 60001–60003) and monitor for suspicious registry persistence mechanisms using Sysmon and Windows Event ID 4698.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.