Description
GoldMax is a second stage command and control backdoor written in Go, with Windows and Linux variants of nearly identical functionality. Investigators discovered it in early 2021 during the SolarWinds Compromise investigation, and APT29 has likely used it since at least mid 2019, relying on defense evasion techniques that include avoiding virtualized execution and masking its traffic.
Stats
- First seen
- February 2022
- Last seen
- October 2026
Also known as
Sunshuttle
MITRE ATT&CK techniques
18 techniques across 5 tactics.
Associated groups
Associated campaigns
Alert name variants
| Alert Name |
|---|
| Generic.GoldMax.A.0F52032B |
| Generic.GoldMax.A.6736A5F4 |
| Generic.GoldMax.A.CE0379AC |
| Generic.GoldMax.A.F92A6C30 |
| Text.Trojan.Sunshuttle |
| Win64.Backdoor.GoldMax |
| Win64.Backdoor.Sunshuttle |
| Win64.Trojan.GoldMax |