Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 2 actorsExploits 1 CVE

GOLDVEIN.JAVA

GOLDVEIN.JAVA is a Java-based downloader malware family observed in 2025 Oracle E-Business Suite (EBS) exploitation chains associated with CVE-2025-61882 and related EBS attack activity. Google Threat Intelligence Group (GTIG) described it as a downloader embedded in malicious XSL payloads/templates installed in vulnerable EBS databases. It attempts to fetch a second-stage payload from a command-and-control server, beacons to C2 using traffic disguised as a "TLSv3.1" handshake, and returns execution logs inside an HTML comment. Mandiant reported GOLDVEIN.JAVA was the most frequently observed malware family across its 2025 investigations. The malware was deployed alongside other Java payload families including SAGEGIFT, SAGELEAF, and SAGEWAVE in multi-stage, fileless Oracle EBS attack chains designed to evade file-based detection. Successful exploitation activity was observed as early as August 2025, with suspicious precursor activity noted in July 2025. Mandiant attributed related Oracle EBS activity to a suspected FIN11 cluster based on use of the CL0P data leak site and the Java-based GOLDVEIN.JAVA downloader, while GTIG noted overlaps with FIN11 but did not make definitive attribution. The malware was also reported as having an earlier PowerShell version first seen in Cleo attacks in December 2024. High-confidence targeting in the provided content is Oracle E-Business Suite environments, with dozens of organizations reportedly affected and significant data theft reported in some cases.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-61882Unauthenticated RCE in Oracle E-Business Suite Concurrent Processing BI Publisher IntegrationExploited in the wild

It has since been determined that hackers likely exploited known EBS vulnerabilities patched in July, likely along with a zero-day flaw tracked as CVE-2025-61882. The hacker groups ShinyHunters and Scattered Spider ... have published a proof-of-concept (PoC) exploit that appears to target CVE-2025-61882 ... according to Oracle, CVE-2025-61882 allows unauthenticated remote code execution. CrowdStrike has found evidence that exploitation of CVE-2025-61882 started on August 9. | One of them is a downloader tracked by Google as GoldVein.Java, which attempts to fetch a second-stage payload from a C&C server.

via security weeksecurityweek.com
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
FIN11

One of them is a downloader tracked by Google as GoldVein.Java, which attempts to fetch a second-stage payload from a C&C server.

via security weeksecurityweek.com
UNC5936

GTIG found two Java payload chains embedded in XSL payloads used in the Oracle EBS campaign: GOLDVEIN.JAVA (downloader) — a Java downloader that beacons to a C2 (disguised as a “TLSv3.1” handshake) and returns execution logs inside an HTML comment.

via securityaffairssecurityaffairs.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence2

It has since been determined that hackers likely exploited known EBS vulnerabilities patched in July, likely along with a zero-day flaw tracked as CVE-2025-61882.

Execution

2 techniques
T1059.005Visual BasicEvidence1
TacticExecution

Mandiant... attributes the activity to a suspected FIN11 cluster, based on use of the CL0P data leak site and the Java-based GOLDVEIN.JAVA downloader.

T1203Exploitation for Client ExecutionEvidence1
TacticExecution

The attackers created a malicious template in vulnerable Oracle EBS databases, which stored a payload triggered in the final stage of the exploit chain.

Stealth

1 technique
T1027.011Fileless StorageEvidence1
TacticStealth

GoldVein, SageGift, SageLeaf, and SageWave have been described as sophisticated, multi-stage, fileless malware that can evade file-based detection.

T1071Application Layer ProtocolEvidence1

One of them is a downloader tracked by Google as GoldVein.Java, which attempts to fetch a second-stage payload from a C&C server.

T1105Ingress Tool TransferEvidence1

One of them is a downloader tracked by Google as GoldVein.Java, which attempts to fetch a second-stage payload from a C&C server.

ACTIVITY FEED

Recent activity

6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.