ESET researchers have discovered attacks by GoldenJackal hackers targeting air-gapped systems in government organizations.

The attacks were part of an espionage campaignthat began in May 2022 and continued until March 2024. The attackers used a series of custom tools designed to penetrate isolated systems, particularly those that did not have direct access to the Internet.
GoldenJackal hackers
ESET has identified the activities of the GoldenJackal group, which has been active since 2019. At that time, it targeted a South Asian embassy in Belarus. During this campaign, GoldenJackal used a custom toolkit that specifically targeted air-gapped systems.
See also: Ukrainian hackers behind the attack on Russian VGTRK?
Some of the main malware used by the GoldenJackal hackers are:
GoldenDealer: Made it easier to transfer malicious files via USB drives
GoldenHowl: A modular backdoor that collects and steals data
GoldenRobo: A tool that collects and steals files from compromised systems
ESET also discovered the most recent attacks (May 2022-March 2024) on air-gapped systems of a European Union government organization.
In these attacks, GoldenJackal hackers upgraded their toolkit to more effectively persist in networks, collect and distribute files, and manage configurations on targeted systems.
See also: Microsoft and DOJ targeted the infrastructure of Russian hackers ColdRiver
"Some hosts were abused for file extraction, others were used as local servers for downloading and distributing staged files or configuration files, and others were deemed interesting for file collection for espionage purposes," ESET explained.
According to researchers, the GoldenJackal hackers primarily target government and diplomatic entities in Europe, South Asia, and the Middle East. The goal is primarily to steal confidential information, particularly from air-gapped systems.
While ESET linked the tools to GoldenJackal, the group's origins remain unclear. However, there may be some connection to Russia, as similarities have been identified with malware attributed to Russian-speaking groups.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“In the GoldenHowl malware, the C&C protocol is referred to as transport_http, an expression commonly used by Turla […] and MoustachedBouncer. This may indicate that the GoldenHowl developers are Russian-speaking,” ESET wrote.
See also: CeranaKeeper hackers target Southeast Asia
The attacks by the GoldenJackal hackers serve as a reminder that air-gapped systems, while often considered more secure, are not immune to cyberattacks . These attacks highlight the need for a comprehensive security strategy that includes both physical and digital measures.
Additionally, these attacks highlight the need for strong cybersecurity policies and procedures within government organizations. This includes regular training for employees, as well as strict access and protocols for handling sensitive information. By taking a proactive approach to cybersecurity, organizations can better protect themselves from advanced threats like GoldenJackal.
Source: www.infosecurity-magazine.com
