{"id":4159,"date":"2022-04-28T12:38:22","date_gmt":"2022-04-28T17:38:22","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4159"},"modified":"2022-04-28T12:38:23","modified_gmt":"2022-04-28T17:38:23","slug":"malware-goldbackdoor-targets-journalists-information","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/","title":{"rendered":"Malware GoldBackdoor targets journalists information"},"content":{"rendered":"\n<p>Sophisticated hackers believed to be linked to the North Korean government are actively targeting journalists with new malware dubbed Goldbackdoor. The attacks have consisted of a multi-stage infection campaign with the ultimate goal of stealing sensitive information from the targets.<\/p>\n\n\n\n<p>These threat actors allegedly the work of Ricochet Chollima target journalists because they are a valuable target for hostile governments.<\/p>\n\n\n\n<p>Ricochet Chollima, also known as APT37InkySquid and ScarCruft is a North Korean nexus-led intruder who has been involved in espionage attacks since at least 2016. The threat actor has a history of attacking the Republic of Korea, with a prominent focus on North Korean government officials, non-governmental organizations, academics, journalists, and defectors.<\/p>\n\n\n\n<p>It is worth noting that this is not the first time that APT37 has been linked to malware campaigns targeting journalists, the most recent being a November 2021 report employing the highly customizable &#8220;Chinotto&#8221; backdoor.<\/p>\n\n\n\n<p>Goldbackdoor runs as a PE (portable executable) file and can remotely accept basic commands and exfiltrate data and for this, it comes with a set of API keys that it uses to authenticate to Azure and retrieve commands for execution. These commands are related to keylogging, file operations, basic RCE, and the ability to uninstall.<\/p>\n\n\n\n<p>Also, it is noteworthy that the malware uses legitimate cloud services for file exfiltration, and Stairwell noted the abuse of Google Drive and Microsoft OneDrive, the files Goldbackdoor targets are mainly documents and media, such as PDF, DOCX, MP3 , TXT, M4A, JPC, XLS, PPT, BIN, 3GP and MSG.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The information handled by journalists may be very dear to certain people and GoldBackdoor maliciously targets this information&#8230;&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4160,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4159","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Malware GoldBackdoor targets journalists information - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"The information handled by journalists may be very dear to certain people and GoldBackdoor maliciously targets this information......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Malware GoldBackdoor targets journalists information - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"The information handled by journalists may be very dear to certain people and GoldBackdoor maliciously targets this information......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-04-28T17:38:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-04-28T17:38:23+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/Gold.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1125\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Malware GoldBackdoor targets journalists information\",\"datePublished\":\"2022-04-28T17:38:22+00:00\",\"dateModified\":\"2022-04-28T17:38:23+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/\"},\"wordCount\":255,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/Gold.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/\",\"name\":\"Malware GoldBackdoor targets journalists information - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/Gold.jpg\",\"datePublished\":\"2022-04-28T17:38:22+00:00\",\"dateModified\":\"2022-04-28T17:38:23+00:00\",\"description\":\"The information handled by journalists may be very dear to certain people and GoldBackdoor maliciously targets this information......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/Gold.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/Gold.jpg\",\"width\":1920,\"height\":1125},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/malware-goldbackdoor-targets-journalists-information\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Malware GoldBackdoor targets journalists information\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Malware GoldBackdoor targets journalists information - Truxgo Server Blog","description":"The information handled by journalists may be very dear to certain people and GoldBackdoor maliciously targets this information......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/","og_locale":"es_MX","og_type":"article","og_title":"Malware GoldBackdoor targets journalists information - Truxgo Server Blog","og_description":"The information handled by journalists may be very dear to certain people and GoldBackdoor maliciously targets this information......","og_url":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-04-28T17:38:22+00:00","article_modified_time":"2022-04-28T17:38:23+00:00","og_image":[{"width":1920,"height":1125,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/Gold.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Malware GoldBackdoor targets journalists information","datePublished":"2022-04-28T17:38:22+00:00","dateModified":"2022-04-28T17:38:23+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/"},"wordCount":255,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/Gold.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/","url":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/","name":"Malware GoldBackdoor targets journalists information - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/Gold.jpg","datePublished":"2022-04-28T17:38:22+00:00","dateModified":"2022-04-28T17:38:23+00:00","description":"The information handled by journalists may be very dear to certain people and GoldBackdoor maliciously targets this information......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/Gold.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/Gold.jpg","width":1920,"height":1125},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/malware-goldbackdoor-targets-journalists-information\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Malware GoldBackdoor targets journalists information"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4159"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4159\/revisions"}],"predecessor-version":[{"id":4170,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4159\/revisions\/4170"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4160"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}