The ink-stained trail of GOLDBACKDOOR
2022-04-21 • Stairwell •
Attachments
Stairwell analyzed a GOLDBACKDOOR deployment chain from malicious artifacts NK News received in a spear-phishing campaign targeting journalists focused on the DPRK. The campaign delivered a ZIP containing a large Windows shortcut named “Kang Min-chol Edits 2.lnk,” which opened a decoy document while running PowerShell to stage additional code. Stairwell assessed with medium-high confidence that GOLDBACKDOOR is a successor to, or used alongside, BLUELIGHT malware attributed to APT37/Ricochet Chollima, based on technical overlaps and the impersonation of DPRK-focused media. The infrastructure included a dailynk.us domain likely chosen to mimic Daily NK, and the multi-stage design allowed the actor to separate initial infection from final payload deployment.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 485246b411ef5ea9e903397a5490d10… | 2022-04-21 | 2025-04-01 |
| URL | https://1drv.ms/u/s!Ar9zfrwxWWE… | 2022-04-21 | 2022-04-27 |
| YARA | NK_GOLDBACKDOOR_Main | 2022-04-21 | 2022-04-21 |
| YARA | NK_GOLDBACKDOOR_generic_shellco… | 2022-04-21 | 2022-04-21 |
| YARA | NK_GOLDBACKDOOR_injected_shellc… | 2022-04-21 | 2022-04-21 |
| YARA | NK_GOLDBACKDOOR_inital_shellcode | 2022-04-21 | 2022-04-21 |
| YARA | NK_GOLDBACKDOOR_obf_payload | 2022-04-21 | 2022-04-21 |
| YARA | NK_GOLDBACKDOOR_LNK_payload | 2022-04-21 | 2022-04-21 |
| YARA | NK_GOLDBACKDOOR_LNK | 2022-04-21 | 2022-04-21 |
| HASH | 9eddd99db6f5a7791f7e446792f04b3… | 2022-04-21 | 2022-04-21 |
| HASH | 18c9fd4f781789cd15cee4fcb18fa98… | 2022-04-21 | 2022-04-21 |
| HASH | 94ca32c0a3002574d7ea1bef094146a… | 2022-04-21 | 2022-04-21 |
| HASH | c5369c2ce7f33d6cd209cd61226a063… | 2022-04-21 | 2022-04-21 |
| HASH | 120ca851663ef0ebef585d716c9e2ba… | 2022-04-21 | 2022-04-21 |
| URL | https://api.onedrive.com/v1.0/s… | 2022-04-21 | 2022-04-21 |
| URL | https://main.dailynk.us/regex?i… | 2022-04-21 | 2022-04-21 |
| DOMAIN | main.dailynk.us | 2022-04-21 | 2022-04-21 |
| IPv4 | 142.93.201.77 | 2022-04-21 | 2022-04-21 |