Description
GoldFinder is a custom HTTP tracer tool written in Go that logs the route a packet takes between a compromised network and a command and control server. Threat actors can use it to identify points that might discover or log their activity, and investigators discovered it in early 2021 during the SolarWinds Compromise investigation into APT29.
Stats
- First seen
- May 2022
- Last seen
- September 2026
Also known as
Goldfinder
MITRE ATT&CK techniques
3 techniques across 3 tactics.
Associated groups
Associated campaigns
Alert name variants
| Alert Name |
|---|
| Win64.Trojan.Goldfinder |
| Win64.Trojan.GoldFinder |