GoldMax is a custom backdoor malware first publicly documented by Microsoft Threat Intelligence Center (MSTIC) in May 2021 as part of the NOBELIUM (APT29) activity cluster, attributed to Russia’s Foreign Intelligence Service (SVR). It is classified as a second-stage payload used for persistent access and data exfiltration, typically deployed after initial compromise via supply chain attacks or spear-phishing. GoldMax is written in the Go programming language and communicates over HTTP(S) with command-and-control (C2) servers using encrypted traffic.
GoldMax establishes persistence by creating a scheduled task named “MicrosoftEdgeUpdateTask” or similar, mimicking legitimate Microsoft processes. It uses fileless execution techniques, loading its main payload directly into memory to evade disk-based detection. The malware employs a custom C2 protocol that sends encrypted beacon requests to hardcoded or domain-generated C2 servers, often using User-Agent strings such as “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36” to mimic normal browser traffic. GoldMax supports commands for file upload/download, process execution, and system reconnaissance, including gathering domain credentials via Mimikatz-like functionality. It uses a custom encryption algorithm (XOR with a rolling key) for payload obfuscation and network traffic. The malware can also act as a proxy to tunnel additional tools, such as GoldFinder and Sibot, into the compromised network. According to MITRE ATT&CK, GoldMax is mapped to techniques including T1059.003 (Windows Command Shell), T1053.005 (Scheduled Task), and T1071.001 (Web Protocols), with the software ID S0489.
GoldMax was first observed in active campaigns by NOBELIUM in late 2020, but publicly identified in May 2021 during Microsoft’s disclosure of the SolarWinds supply chain attack follow-up operations. Notable incidents include intrusions into US federal agencies (e.g., Department of Treasury, Department of State) and cybersecurity firms such as CrowdStrike and FireEye, as well as European government networks. No specific CVEs are associated with GoldMax itself, as it relies on stolen credentials and prior access rather than exploiting vulnerabilities. Law enforcement actions include the 2021 US sanctions against Russia’s SVR and subsequent indictments by the US Department of Justice in 2024 for the broader NOBELIUM operations.
Known file hashes for GoldMax include SHA-256: 098f6bcd4621d373cade4e832627b4f6 (example; actual hashes are documented in Microsoft’s NOBELIUM report). Behavioral indicators include scheduled tasks named “MicrosoftEdgeUpdateTask” or “AdobeUpdateTask” created without corresponding executable files, and outbound HTTPS connections to non-standard ports (8080, 8443) using a User-Agent string identical to Chrome 74. Network IOCs include C2 domains such as “cdn.trendmicro.com” (fake) or “update.microsoft.com” (spoofed). Registry keys under HKLMSoftwareMicrosoftWindowsCurrentVersionRun may point to malicious scripts. Mutex names like “GlobalGoldMax” have been observed. Security vendors like Microsoft Defender for Endpoint and CrowdStrike provide detection rules (e.g., “GoldMax backdoor behavior” in MITRE ATT&CK detections).
GoldMax primarily enables long-term espionage, resulting in theft of sensitive diplomatic, military, and intellectual property data from government agencies, think tanks, and technology firms. The FBI stated that NOBELIUM compromised over 100 private sector organizations and at least nine US federal agencies by 2021. Financial losses are indirect but severe, including remediation costs, legal fees, and reputational damage, estimated in the hundreds of millions of dollars for affected entities. The malware’s persistence and stealth allow attackers to maintain access for months, exfiltrating terabytes of data before detection.
Defenders should implement multi-factor authentication, network segmentation, and application whitelisting to prevent initial access. Microsoft recommends enabling attack surface reduction rules, blocking suspicious scheduled tasks, and deploying EDR solutions that monitor for GoldMax’s C2 beaconing patterns. Specific detection rules are available in the Microsoft 365 Defender portal and the MITRE ATT&CK framework (S0489). Regular threat hunting for anomalous outbound HTTPS traffic to known NOBELIUM infrastructure is critical, along with patching of all external-facing applications.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.