Goldbackdoor Malware
Summary
The particular hacker group is tracked by cybersecurity organizations under several different names - APT37, InkySquid, Reaper, ScarCruft and Ricochet Collima. The threatening operation is believed to have started at some point in March 2022 with the primary goal of collecting sensitive information from the targets. Analysis of the threat carried out by researchers has revealed that Goldbackdoor is a multi-stage malware with an expanded set of threatening capabilities. Due to the significant similarities and overlap within the code and its behavior, the experts state that the new threat is most likely a successor of the Bluelight malware, one of the harmful instruments used by APT37 in the past. Once enabled, Goldbackdoor provides the threat actors with the ability to execute remote commands, exfiltrate data, collect files or download additional ones to the breached machine, establish keylogging routines and more.