×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET: APT GoldenJackal group aims at European targets to steal sensitive data with tools capable of operating in an air gap

Customer Press Room

ESET: APT GoldenJackal group aims at European targets to steal sensitive data with tools capable of operating in an air gap

by Grandangolo Communications / Thursday, 10 October 2024 / Published in Eset

GoldenJackal's ultimate goal is most likely cyberespionage, particularly targeting high-profile systems purposely isolated from the Internet

Researchers of ESET, a global European leader in the cybersecurity market, have discovered a series of attacks that occurred in Europe between May 2022 and March 2024, in which attackers used a toolset capable of targeting air-gapped systems, in a government organization in a European Union country. ESET attributes the campaign to GoldenJackal, an APT cyberespionage group that targets government and diplomatic entities. By analyzing the toolset used by the group, ESET identified an attack that GoldenJackal carried out in 2019 with customized tools targeting the air-gapped systems of a South Asian embassy in Belarus. GoldenJackal's ultimate goal is most likely to steal confidential and highly sensitive information, especially from high-profile machines that may not be connected to the Internet. ESET Research presented its findings at the Virus Bulletin 2024 conference.

To minimize the risk of compromise, highly sensitive networks are often air-gapped, that is, separated from other networks. Typically, organizations isolate their most valuable systems, such as voting systems and the industrial control systems that manage electrical grids. These are often prime targets for attackers. Compromising an isolated network is much more complex than breaching an Internet-connected system, which means that frameworks designed to attack isolated networks have so far been developed exclusively by APT groups. The purpose of such attacks is always espionage.

"In May 2022, we discovered a toolset that we could not attribute to any APT group. But once the attackers used a tool similar to one of the already documented ones, we managed to find a link between GoldenJackal's known toolset and the new one. With further digging, we identified a previous attack in which the documented toolset had been deployed, as well as an older toolset that also has capabilities to attack air-gapped systems," explains ESET researcher Matías Porolli, who analyzed the GoldenJackal toolset.

GoldenJackal has targeted government entities in Europe, the Middle East and South Asia. ESET detected GoldenJackal tools at a South Asian embassy in Belarus in August and September 2019 and again in July 2021. More recently, according to ESET telemetry, another government organization in Europe was repeatedly attacked from May 2022 to March 2024.

With the level of sophistication required, it is quite unusual that in five years GoldenJackal managed to deploy not one, but two separate toolsets designed to compromise isolated systems. This demonstrates the group's remarkable ability to adapt. The attacks against a South Asian embassy in Belarus used customized tools that we have only seen in that specific context. The campaign used three main components: GoldenDealer to distribute executables to the air-gapped system via USB monitoring; GoldenHowl, a modular backdoor with various features; and GoldenRobo, a file collector and exfiltrator.

"When a victim inserts a compromised USB drive into an air-gapped system and clicks on a component that has a folder icon but is actually a malicious executable, GoldenDealer is installed and started, which begins to collect information about the air-gapped system and stores it on the USB drive. When the drive is inserted again into an Internet-connected PC, GoldenDealer takes information about the air-gapped PC from the USB drive and sends it to the C&C (Command&Control) server. The server responds with a or more executables to launch on the air-gapped system. Finally, when the drive is inserted back into the air-gapped system, GoldenDealer launches the executables taken from the drive, as GoldenDealer is already running,” explains Porolli.

In its latest series of attacks against a government organization in the European Union, GoldenJackal has switched from the original toolset to a new, highly modular one. This modular approach applied not only to the malicious tools, but also to the roles of the breached hosts within the compromised system: they were used, among other things, to collect and process sensitive information, distribute files, configurations and commands to other systems, and exfiltrate files.

For a more detailed analysis and in-depth technical explanation of GoldenJackal's tools, see ESET Research's latest blog post, “Mind the (air) gap: GoldenJackal gooses government guardrails” on WeLiveSecurity.com. Follow ESET Research on Twitter (now known as X) For the latest news from ESET Research.

Tagged under: Eset

About Grandangolo Communications

What you can read next

ESET Research has discovered CloudMensis, a new threat for attacks targeting Mac users
ESET was recognized as a Top Player in Radicati's 2024 Market Quadrant for the APT Protection segment
IDC MarketScape names ESET Major Player in two next-generation endpoint security reports

Customer Press Room

  • ESET Research: FamousSparrow steps up operations in Latin America and hits governments with new backdoor

    The pro-Chinese APT group concentrates its activities...
  • ESET's ultra-fast, high-accuracy threat detection scanner, now available in AWS Marketplace

    The ESET PRIVATE Scanning Solutions suite is available...
  • Arrow Electronics signs distribution agreement with Usercentrics

    Arrow Electronics, a global supplier of technology...
  • Acronis names Denis Cassinerio Vice President South Europe CEE

    In the new role the manager will continue the...
  • SentinelOne enhances Wayfinder's Frontier AI services by integrating OpenAI's Daybreak models

    Advanced cybersecurity services expanded with...

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Imprivate
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP