Goldbackdoor Malware

General News

Summary

The particular hacker group is tracked by cybersecurity organizations under several different names - APT37, InkySquid, Reaper, ScarCruft and Ricochet Collima. The threatening operation is believed to have started at some point in March 2022 with the primary goal of collecting sensitive information from the targets. Analysis of the threat carried out by researchers has revealed that Goldbackdoor is a multi-stage malware with an expanded set of threatening capabilities. Due to the significant similarities and overlap within the code and its behavior, the experts state that the new threat is most likely a successor of the Bluelight malware, one of the harmful instruments used by APT37 in the past. Once enabled, Goldbackdoor provides the threat actors with the ability to execute remote commands, exfiltrate data, collect files or download additional ones to the breached machine, establish keylogging routines and more.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M