Stairwell threat report: The ink-stained trail of GOLDBACKDOOR
ID: a42246d3-b53f-4b6c-bb2e-11b4f0735439
STIX ID: report--a42246d3-b53f-4b6c-bb2e-11b4f0735439
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2022-04-22
Last Modified Date: 2022-04-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Stairwell's report analyzes a targeted spear-phishing campaign that delivered a multi-stage loader (via a padded LNK in a ZIP) which decodes and executes XOR-encoded shellcode (Fantasy) that injects a PE backdoor named GOLDBACKDOOR; the backdoor (linked to APT37/BLUELIGHT) uses cloud services (OneDrive/Google Drive/Azure/Graph APIs) for C2, supports file collection, keylogging, remote commands, and includes operational tracking via externally hosted resources. The report provides technical artifacts, YARA rules, infrastructure indicators (main.dailynk.us, 142.93.201.77), and file hashes to aid detection and attribution.
