Skip to content

Incidents attributed to:

GoldenJackal

GoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic.

GoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic. Kaspersky believes the attackers upload a malicious PHP file that is used as a relay to forward web requests to another backbone C2 server. They developed a collection of .NET malware tools known as Jackal.

References


Actor metadata imported from Malpedia (Fraunhofer FKIE).