EVILNUM
TA4563
Threat IntelligenceAPTFebruary 17, 202615 min read

GoldMouse: Threat Intelligence Profile

Financially motivated APT targeting fintech and cryptocurrency companies using the Golden Chickens MaaS suite and custom JavaScript malware.

Scroll

GoldMouse / Evilnum (also known as Evilnum, TA4563) is a state-sponsored advanced persistent threat group attributed to Unknown (financially motivated), active since 2018. The group primarily targets fintech, forex, cryptocurrency companies sectors. It is tracked by MITRE ATT&CK as G0120.

Overview & Attribution

Financially motivated APT targeting fintech and cryptocurrency companies using the Golden Chickens MaaS suite and custom JavaScript malware.

Threat Assessment

GoldMouse has been active since 2018, attributed to Unknown (financially motivated). The group is known for targeting fintech, forex, cryptocurrency companies using a combination of custom malware, living-off-the-land techniques, and sophisticated social engineering.

Arsenal & Tools

GoldMouse employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

The group focuses on fintech, forex, cryptocurrency companies sectors, with operations spanning multiple geographic regions. Their campaigns typically involve carefully crafted spearphishing, strategic watering holes, and exploitation of public-facing applications.

Operational Pattern

GoldMouse is characterized by persistent, long-term access operations. Once inside a target network, the group establishes multiple redundant persistence mechanisms and moves laterally to high-value systems before beginning data exfiltration.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1566.001 Phishing AttachmentKYC document lures
ExecutionT1059.007 JavaScriptJS-based malware execution
PersistenceT1547.001 Registry Run KeysAutostart persistence
CollectionT1113 Screen CaptureDesktop screenshots
CollectionT1005 Data from Local SystemFinancial data theft
C2T1071.001 Web ProtocolsHTTP/HTTPS C2

Notable Campaigns

GoldMouse has been linked to multiple significant campaigns targeting fintech, forex, cryptocurrency companies organizations. The group continuously evolves its tooling and infrastructure to evade detection while maintaining persistent access to compromised networks.

Detection & Defense

Defend Against GoldMouse

Mjolnir Security provides specialized capabilities to detect and respond to GoldMouse operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for GoldMouse TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of GoldMouse campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: February 17, 2026