LevelBlue + SentinelOne Partner to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

LevelBlue SpiderLabs threat hunting experts investigate a malware campaign targeting corporations operating in China. This report identifies a new threat and provides specific hunting, investigative, and remediation methodologies that can be used to help ensure your environment is clean.

Use this information to empower your organization, if you have operations in China or are planning to start operations there, to fight this unattributed threat actor group today, with sections covering:

  • The Golden Tax Department and Emergence of GoldenSpy Malware
  • Associated Indicators of Compromise (IOC’s) and IOC’s associated with the network architecture used with this threat
  • Malware analysis and malware reverse engineering reports
  • Recommended risk mitigation measures

Related Resources

Current: resourcesresearch-reportsthe-golden-tax-department-and-emergence-of-goldenspy-malware
Resource: resourcesresearch-reportsttp-briefing-q1-2026
Research Report

Q1 2026 TTP Briefing: Latest Threats & Trends from the Frontlines

Current: resourcesresearch-reportsthe-golden-tax-department-and-emergence-of-goldenspy-malware
Resource: resourcesresearch-reportsan-in-depth-analysis-of-novel-karstorat-malware
Research Report

An In-Depth Analysis of Novel KarstoRAT Malware

Current: resourcesresearch-reportsthe-golden-tax-department-and-emergence-of-goldenspy-malware
Resource: resourcesresearch-reportscyber-resilience-insights-for-ctos
Research Report

Cyber Resilience Insights for CTOs