Skip to content

Malware

GoldMax

aka SUNSHUTTLE

Gold Max is a Golang written command and control backdoor used by the NOBELIUM threat actor group.

GoldMax, also known as SUNSHUTTLE, is a Windows malware family operated by UNC2452.

Background

GoldMax is a command-and-control backdoor coded in Golang and wielded by the NOBELIUM threat group. It applies a variety of obfuscation methods to mask its behavior and dodge detection. The backdoor drops an encrypted configuration file to disk whose filename and AES-256 keys are unique to each implant, derived from environment variables and details about the network it operates on.


Source: Malpedia (Fraunhofer FKIE).