GoldenJackal is an unknown threat actor targeting German victims using WordPress-based C2 and the Jackal .NET toolset.
Analyst brief
GoldenJackal is an unknown threat actor. It primarily targets victims in Germany. The actor uses compromised WordPress websites to host C2 relay logic and employs a .NET malware toolset called Jackal. Defenders should monitor for suspicious PHP files, WordPress-based C2 traffic, and unknown .NET execution activities in the environment.
GoldenJackal
unknown
GoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic. Kaspersky believes the attackers upload a malicious PHP file that is used as a relay to forward web requests to another backbone C2 server. They developed a collection of .NET malware tools known as Jackal.
What method does GoldenJackal use to conceal its C2 communication?+
GoldenJackal uses compromised WordPress websites to host C2 relay logic by uploading a malicious PHP file that forwards web requests to a backbone C2 server.
What is the name of the malware toolset used by GoldenJackal?+
GoldenJackal uses a collection of .NET malware tools known as 'Jackal'.