logo

Stairwell threat report: The ink-stained trail of GOLDBACKDOOR

ID: a42246d3-b53f-4b6c-bb2e-11b4f0735439

STIX ID: report--a42246d3-b53f-4b6c-bb2e-11b4f0735439

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2022-04-22

Last Modified Date: 2022-04-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Stairwell's report analyzes a targeted spear-phishing campaign that delivered a multi-stage loader (via a padded LNK in a ZIP) which decodes and executes XOR-encoded shellcode (Fantasy) that injects a PE backdoor named GOLDBACKDOOR; the backdoor (linked to APT37/BLUELIGHT) uses cloud services (OneDrive/Google Drive/Azure/Graph APIs) for C2, supports file collection, keylogging, remote commands, and includes operational tracking via externally hosted resources. The report provides technical artifacts, YARA rules, infrastructure indicators (main.dailynk.us, 142.93.201.77), and file hashes to aid detection and attribution.