Netskope Threat Labs

GoldMax

ATP Sandbox Adv. HeuristicsAV

GoldMax is a second stage command and control backdoor written in Go, with Windows and Linux variants of nearly identical functionality. Investigators discovered it in early 2021 during the SolarWinds Compromise investigation, and APT29 has likely used it since at least mid 2019, relying on defense evasion techniques that include avoiding virtualized execution and masking its traffic.

First seen
February 2022
Last seen
October 2026
Sunshuttle

18 techniques across 5 tactics.

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1124System Time Discovery

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
Alert Name
Generic.GoldMax.A.0F52032B
Generic.GoldMax.A.6736A5F4
Generic.GoldMax.A.CE0379AC
Generic.GoldMax.A.F92A6C30
Text.Trojan.Sunshuttle
Win64.Backdoor.GoldMax
Win64.Backdoor.Sunshuttle
Win64.Trojan.GoldMax