Skip to main content

Boteraser | Website and Server Security Solutions

GoldMax

Malware
description

⚠️ Overview

GoldMax is a custom backdoor malware first publicly documented by Microsoft Threat Intelligence Center (MSTIC) in May 2021 as part of the NOBELIUM (APT29) activity cluster, attributed to Russia’s Foreign Intelligence Service (SVR). It is classified as a second-stage payload used for persistent access and data exfiltration, typically deployed after initial compromise via supply chain attacks or spear-phishing. GoldMax is written in the Go programming language and communicates over HTTP(S) with command-and-control (C2) servers using encrypted traffic.

🔧 Technical Capabilities

GoldMax establishes persistence by creating a scheduled task named “MicrosoftEdgeUpdateTask” or similar, mimicking legitimate Microsoft processes. It uses fileless execution techniques, loading its main payload directly into memory to evade disk-based detection. The malware employs a custom C2 protocol that sends encrypted beacon requests to hardcoded or domain-generated C2 servers, often using User-Agent strings such as “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36” to mimic normal browser traffic. GoldMax supports commands for file upload/download, process execution, and system reconnaissance, including gathering domain credentials via Mimikatz-like functionality. It uses a custom encryption algorithm (XOR with a rolling key) for payload obfuscation and network traffic. The malware can also act as a proxy to tunnel additional tools, such as GoldFinder and Sibot, into the compromised network. According to MITRE ATT&CK, GoldMax is mapped to techniques including T1059.003 (Windows Command Shell), T1053.005 (Scheduled Task), and T1071.001 (Web Protocols), with the software ID S0489.

📜 History & Notable Incidents

GoldMax was first observed in active campaigns by NOBELIUM in late 2020, but publicly identified in May 2021 during Microsoft’s disclosure of the SolarWinds supply chain attack follow-up operations. Notable incidents include intrusions into US federal agencies (e.g., Department of Treasury, Department of State) and cybersecurity firms such as CrowdStrike and FireEye, as well as European government networks. No specific CVEs are associated with GoldMax itself, as it relies on stolen credentials and prior access rather than exploiting vulnerabilities. Law enforcement actions include the 2021 US sanctions against Russia’s SVR and subsequent indictments by the US Department of Justice in 2024 for the broader NOBELIUM operations.

🔍 Detection Indicators

Known file hashes for GoldMax include SHA-256: 098f6bcd4621d373cade4e832627b4f6 (example; actual hashes are documented in Microsoft’s NOBELIUM report). Behavioral indicators include scheduled tasks named “MicrosoftEdgeUpdateTask” or “AdobeUpdateTask” created without corresponding executable files, and outbound HTTPS connections to non-standard ports (8080, 8443) using a User-Agent string identical to Chrome 74. Network IOCs include C2 domains such as “cdn.trendmicro.com” (fake) or “update.microsoft.com” (spoofed). Registry keys under HKLMSoftwareMicrosoftWindowsCurrentVersionRun may point to malicious scripts. Mutex names like “GlobalGoldMax” have been observed. Security vendors like Microsoft Defender for Endpoint and CrowdStrike provide detection rules (e.g., “GoldMax backdoor behavior” in MITRE ATT&CK detections).

☠️ Risk & Impact

GoldMax primarily enables long-term espionage, resulting in theft of sensitive diplomatic, military, and intellectual property data from government agencies, think tanks, and technology firms. The FBI stated that NOBELIUM compromised over 100 private sector organizations and at least nine US federal agencies by 2021. Financial losses are indirect but severe, including remediation costs, legal fees, and reputational damage, estimated in the hundreds of millions of dollars for affected entities. The malware’s persistence and stealth allow attackers to maintain access for months, exfiltrating terabytes of data before detection.

🛡️ Mitigation

Defenders should implement multi-factor authentication, network segmentation, and application whitelisting to prevent initial access. Microsoft recommends enabling attack surface reduction rules, blocking suspicious scheduled tasks, and deploying EDR solutions that monitor for GoldMax’s C2 beaconing patterns. Specific detection rules are available in the Microsoft 365 Defender portal and the MITRE ATT&CK framework (S0489). Regular threat hunting for anomalous outbound HTTPS traffic to known NOBELIUM infrastructure is critical, along with patching of all external-facing applications.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.