GoldenJackal's ultimate goal is most likely cyberespionage, particularly targeting high-profile systems purposely isolated from the Internet
Researchers of ESET, a global European leader in the cybersecurity market, have discovered a series of attacks that occurred in Europe between May 2022 and March 2024, in which attackers used a toolset capable of targeting air-gapped systems, in a government organization in a European Union country. ESET attributes the campaign to GoldenJackal, an APT cyberespionage group that targets government and diplomatic entities. By analyzing the toolset used by the group, ESET identified an attack that GoldenJackal carried out in 2019 with customized tools targeting the air-gapped systems of a South Asian embassy in Belarus. GoldenJackal's ultimate goal is most likely to steal confidential and highly sensitive information, especially from high-profile machines that may not be connected to the Internet. ESET Research presented its findings at the Virus Bulletin 2024 conference.
To minimize the risk of compromise, highly sensitive networks are often air-gapped, that is, separated from other networks. Typically, organizations isolate their most valuable systems, such as voting systems and the industrial control systems that manage electrical grids. These are often prime targets for attackers. Compromising an isolated network is much more complex than breaching an Internet-connected system, which means that frameworks designed to attack isolated networks have so far been developed exclusively by APT groups. The purpose of such attacks is always espionage.
"In May 2022, we discovered a toolset that we could not attribute to any APT group. But once the attackers used a tool similar to one of the already documented ones, we managed to find a link between GoldenJackal's known toolset and the new one. With further digging, we identified a previous attack in which the documented toolset had been deployed, as well as an older toolset that also has capabilities to attack air-gapped systems," explains ESET researcher Matías Porolli, who analyzed the GoldenJackal toolset.
GoldenJackal has targeted government entities in Europe, the Middle East and South Asia. ESET detected GoldenJackal tools at a South Asian embassy in Belarus in August and September 2019 and again in July 2021. More recently, according to ESET telemetry, another government organization in Europe was repeatedly attacked from May 2022 to March 2024.
With the level of sophistication required, it is quite unusual that in five years GoldenJackal managed to deploy not one, but two separate toolsets designed to compromise isolated systems. This demonstrates the group's remarkable ability to adapt. The attacks against a South Asian embassy in Belarus used customized tools that we have only seen in that specific context. The campaign used three main components: GoldenDealer to distribute executables to the air-gapped system via USB monitoring; GoldenHowl, a modular backdoor with various features; and GoldenRobo, a file collector and exfiltrator.
"When a victim inserts a compromised USB drive into an air-gapped system and clicks on a component that has a folder icon but is actually a malicious executable, GoldenDealer is installed and started, which begins to collect information about the air-gapped system and stores it on the USB drive. When the drive is inserted again into an Internet-connected PC, GoldenDealer takes information about the air-gapped PC from the USB drive and sends it to the C&C (Command&Control) server. The server responds with a or more executables to launch on the air-gapped system. Finally, when the drive is inserted back into the air-gapped system, GoldenDealer launches the executables taken from the drive, as GoldenDealer is already running,” explains Porolli.
In its latest series of attacks against a government organization in the European Union, GoldenJackal has switched from the original toolset to a new, highly modular one. This modular approach applied not only to the malicious tools, but also to the roles of the breached hosts within the compromised system: they were used, among other things, to collect and process sensitive information, distribute files, configurations and commands to other systems, and exfiltrate files.
For a more detailed analysis and in-depth technical explanation of GoldenJackal's tools, see ESET Research's latest blog post, “Mind the (air) gap: GoldenJackal gooses government guardrails” on WeLiveSecurity.com. Follow ESET Research on Twitter (now known as X) For the latest news from ESET Research.






