ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool Gold Dragon

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: Gold Dragon

NamesGold Dragon
CategoryMalware
TypeBackdoor
Description(McAfee) On December 24, 2017, our analysts observed the Korean-language implant Gold Dragon. We now believe this implant is the second-stage payload in the Olympics attack that ATR discovered January 6, 2018. The PowerShell implant used in the Olympics campaign was a stager based on the PowerShell Empire framework that created an encrypted channel to the attacker’s server. However, this implant required additional modules to be executed to be a fully capable backdoor. In addition, the PowerShell implant did not contain a mechanism to persist beyond a simple scheduled task. Gold Dragon has a much more robust persistence mechanism than the initial PowerShell implant and enables the attacker to do much more to the target system. Gold Dragon reappeared the same day that the Olympics campaign began.
Information<https://www.mcafee.com/blogs/other-blogs/mcafee-labs/gold-dragon-widens-olympics-malware-attacks-gains-permanent-presence-on-victims-systems/>
<https://www.cybereason.com/blog/back-to-the-future-inside-the-kimsuky-kgh-spyware-suite>
MITRE ATT&CK<https://attack.mitre.org/software/S0249/>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/win.gold_dragon>

Last change to this tool card: 23 April 2021

Download this tool card in JSON format

Previous: GOGGLES
Next: GoldenEagle

All groups using tool Gold Dragon

ChangedNameCountryObserved

APT groups

 HadesRussia2017-Oct 2020X
 Kimsuky, Velvet ChollimaNorth Korea2012-May 2021X

2 groups listed (2 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key