Blog | G5 Cyber Security

GoldenSpy backdoor installed by tax software gets remotely removed

GoldenSpy was hidden in software called Intelligent Tax, from Aisino Corporation, that a Chinese bank required its company customers to install for paying local taxes. The backdoor runs with the highest privileges on the system, allowing it to execute any software, legitimate or not. As soon as security researchers uncovered the activity, the actor behind it fell back and delivered an uninstall tool to remove all traces of the malware. The actor and the purposes behind the threat remain unclear, the researchers say that the component has characteristics similar to a coordinated advanced persistent (APT) campaign that focuses on foreign companies.

Source: https://www.bleepingcomputer.com/news/security/goldenspy-backdoor-installed-by-tax-software-gets-remotely-removed/

Exit mobile version