Malware
GoldDragon
aka Lovexxx
GoldDragon was a second-stage backdoor which established a permanent presence on the victim’s system once the first-stage, file-less, PowerShell-based attack leveraging steganography was executed.
GoldDragon, also known as Lovexxx, is a Windows malware family.
Background
GoldDragon served as a second-stage backdoor that secured lasting persistence on a victim's machine after the initial fileless, steganography-using, PowerShell-based stage had run. The campaign was first seen in December 2017, when Korean-language spear phishing was aimed at organizations associated with the 2018 Pyeongchang Winter Olympics, and GoldDragon was dropped only after the attacker had already established a foothold in the target environment. Its capabilities covered basic reconnaissance, data exfiltration, and pulling additional components from its C&C server.
Source: Malpedia (Fraunhofer FKIE).