Netskope Threat Labs

GoldFinder

ATP Sandbox Adv. Heuristics

GoldFinder is a custom HTTP tracer tool written in Go that logs the route a packet takes between a compromised network and a command and control server. Threat actors can use it to identify points that might discover or log their activity, and investigators discovered it in early 2021 during the SolarWinds Compromise investigation into APT29.

First seen
May 2022
Last seen
September 2026
Goldfinder

3 techniques across 3 tactics.

TA0007 Discovery

  • T1016System Network Configuration Discovery

TA0009 Collection

  • T1119Automated Collection

TA0011 Command and Control

Alert Name
Win64.Trojan.Goldfinder
Win64.Trojan.GoldFinder