
Middle East and South Asian Governments and Diplomatic Agencies Targeted by New Sophisticated and Persistent Threat Actors golden jackal.
Russian cybersecurity firm Kaspersky has been monitoring the group’s activities since mid-2020 and characterized the adversary as capable and stealthy.
The target scope of the campaign is focused on Afghanistan, Azerbaijan, Iran, Iraq, Pakistan and Turkey, where the purpose-built malware steals data, propagates system-wide via removable drives, and monitors victims. infect.
GoldenJackal is believed to have been active for at least four years, but little is known about the group. Kaspersky said it could not determine its origin or connection to known attackers, but said the attacker’s modus operandi suggested an espionage motive.
Moreover, this threat actor’s attempt to hide and disappear into the shadows has all the hallmarks of a state-backed group.
That said, some tactical overlaps have been observed between this threat actor and Turla, one of Russia’s national elite hacking forces. In one situation, the victim’s machine was infected with Turla and GoldenJackal two months apart.
The exact initial vector used to infiltrate the victim’s computer is currently unknown, but the evidence collected so far is the use of a Trojanized Skype installer and a malicious Microsoft Word document. is shown.
The installer acts as a vehicle for delivering a .NET-based Trojan called JackalControl, while Word files have been observed to leverage the Follina vulnerability (CVE-2022-30190) to drop the same malware. I’m here.
JackalControl, as its name suggests, allows an attacker to remotely take over a machine and execute arbitrary commands, as well as upload and download to and from the system.
![]() |
| Victim Geography |
Some of the other malware families deployed by GoldenJackal are:
- jackal steel – An implant used to search for desired files, such as files on removable USB drives, and send them to a remote server.
- jackal worm – A worm designed to use removable USB drives to infect systems and install the JackalControl Trojan.
- Jackal Per Info – Malware with the ability to collect system metadata, folder contents, installed applications, running processes, and credentials stored in web browser databases.
- Jackal Screen Watcher – A utility that takes screenshots based on preset time intervals and sends them to an attacker-controlled server.
Another notable aspect of this threat actor is that it uses malicious PHP files injected into websites to act as intermediaries to forward web requests to real command and control (C2) servers that have been hacked. It depends on your WordPress site.
“The group is probably trying to reduce its profile by limiting the number of victims,” said Kaspersky researcher Giampaolo Dedra. “Their toolkit appears to be in development. The number of variants indicates they are still investing in the toolkit.”
