ATT&CKSoftwareGoldFinder

GoldFinder

S0597

Malware.View on attack.mitre.org

About this malware

GoldFinder is a custom HTTP tracer tool written in Go that logs the route a packet takes between a compromised network and a C2 server. It can be used to inform threat actors of potential points of discovery or logging of their actions, including C2 related to other malware. GoldFinder was discovered in early 2021 during an investigation into the SolarWinds Compromise by APT29.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1016.001
Internet Connection Discovery

GoldFinder performed HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request traveled through.

T1071.001
Web Protocols

GoldFinder has used HTTP for C2.

T1119
Automated Collection

GoldFinder logged and stored information related to the route or hops a packet took from a compromised machine to a hardcoded C2 server, including the target C2 URL, HTTP response/status code, HTTP response headers and values, and data received from the C2 node.

Groups that use it1

Campaigns1

References1

  1. MSTIC NOBELIUM Mar 2021 Open source
    Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.