Revisiting Voldemort, HealthKick, and GOVERSHELL: A Technical Retrospective

Umut Bayram | 12 MIN READ

| May 20, 2026

Key Takeaways

  • Three malware strains (Voldemort, HealthKick, GOVERSHELL) linked to Chinese state-sponsored espionage from mid-2024 to late 2025.
  • Targeted entities were Taiwanese semiconductor companies and international think tanks through spear-phishing and DLL sideloading.
  • Unique characteristics of Voldemort involve leveraging Google Sheets as a C2 server, mixing its network traffic with Google Workspace services.
  • GOVERSHELL, after its first variant HealthKick, changed its C2 stack five times within five months, suggesting involvement of LLMs in coding.
  • OpenAI stated that ChatGPT was used by the adversary in creating certain components of the attack.
  • Picus Security Validation Platform validates organizations' defenses against Voldemort, HealthKick, and GOVERSHELL malware families.

Three malware families related to espionage operations by Chinese-linked threat actors surfaced between mid-2024 and late 2025. With some time now having elapsed since then and the situation having settled down, it seems appropriate to look back on the technical details of these toolkits together, which have been used to launch attacks against specific targets like Taiwan's semiconductor manufacturers and think tanks across the globe.

In this blog post, we review the delivery, infection techniques, persistence, and C2 architecture employed by these three malware families.

Background: The Three Families and Their Relation

Before we delve into discussing the specifics of each malware family, it might be helpful to provide some context regarding the relation between them.

The first and oldest of the three malware families in question is Voldemort, which was first discovered in August 2024. It represents a unique custom backdoor characterized by the unusual implementation of Google Sheets as its C2 server.

The second malware family under discussion is HealthKick, which was discovered in April 2025. In fact, HealthKick proved to be nothing more than the first version of a wider range of malware, called GOVERSHELL. To put it simply, HealthKick is actually GOVERSHELL v1, coded in C++ and replaced with a fully redesigned GOVERSHELL v2 to v5 variants written in Go.

Altogether, there are five different versions of this malware, each of which uses different C2 communication protocol and encryption algorithms.

It's also important to note that all three malware families are distributed via spear-phishing emails and abuse DLL sideloading technique.

Part 1: Voldemort

Delivery Chain

Voldemort's infection chain is arguably the most elaborate of the three. At a high level:

Phishing Email
→ Google AMP Cache URL
  → InfinityFree-hosted landing page
    → User Agent check (Windows only)
      → search-ms URI (Windows Search)
        → WebDAV share (TryCloudflare)
          → LNK shortcut file
            → Python script (via WebDAV)
              → Voldemort DLL

Google AMP Cache is a caching proxy server for serving webpages belonging to Google's accelerated mobile pages infrastructure. Being a legitimate feature of the system, it is abused by malicious actors because the initial URL redirects to a google.com subdomain, thus bypassing simple URL filters.

First, the landing page performed a User Agent check. If the agent string included windows, the victim would be redirected to a search: URI. Otherwise, they would receive an empty URL that directed to Google Drive, which is a dead end.

When opening a search: URI, Windows silently starts Windows Explorer with the search parameters encoded in the URI, without showing any download prompts or file downloads.

The attackers used this behavior to redirect Windows Explorer to a WebDAV share hosted on TryCloudflare. This service provided a tunnel for accessing the contents of the attacker-controlled site [1]:

File: <redacted>
Type: Shortcut (.lnk)
Icon: PDF


This is a commonly known social engineering technique: the file appears to be a regular PDF document (with an appropriate icon and no lnk extension visible by default), but it's actually located on a remote WebDAV share.

If the LNK is executed, it will launch:

powershell.exe → Python.exe (from \library\ WebDAV share) → script (from \resource\ WebDAV share).

Initial Reconnaissance

After starting, it gathers basic information about the host and sends it through a GET request to a tracker service:

http://<tracking-IP>/p/.../stage2-2/<base64-encoded-host-info>

Then it downloads and displays a decoy PDF that is relevant to the target region.

DLL Sideloading

The real payload is a password-protected ZIP file downloaded from a file hosting service and unpacked to %localappdata%\Microsoft\Windows\. It includes two files:

  • CiscoCollabHost.exe – a legitimate Cisco Webex executable, susceptible to DLL sideloading
  • CiscoSparkLauncher.dll – the malicious DLL

When CiscoCollabHost.exe runs, it tries to find CiscoSparkLauncher.dll first in its own folder, and only after that in the system folder, the expected behavior on Windows. The malicious DLL has a SparkEntryPoint function exported, which is invoked by the binary.

The DLL’s SparkEntryPoint function starts with a sleep of about 5-10 minutes for sandbox evasion. Most automated sandboxing solutions time out before this period elapses, and therefore, any dynamic analysis will not detect any malicious network activity.

Command and Control: Google Sheets

Voldemort authenticates to the Google OAuth2 endpoint using the hardcoded client ID, client secret, and refresh token embedded in its encrypted configuration. The RC4 encryption key used by the malware for the configuration is the filename of the executable, CiscoCollabHost.exe.

The malware performs both write operations and read operations on a particular Google Sheet that acts as the C2 panel:

  • Victim registration: Voldemort iterates through cells A1, A2, A3… until it encounters an empty cell and writes victim host info (encoded to base64 and RC4-encrypted) into that cell. Every row corresponds to a single victim.
  • Command polling: The attacker writes commands into the Sheet; the malware reads those commands and executes them.

File upload/download, arbitrary command execution, copy, move, sleep, and exit are among the available commands. These constitute a fairly comprehensive set of backdoor capabilities.

The malware sends its traffic to sheets.googleapis.com port 443, making it virtually impossible to distinguish from regular enterprise Google Workspace traffic in network logs.

Part 2: HealthKick (GOVERSHELL Variant 1)

HealthKick is the earliest known iteration of what would later become the GOVERSHELL family, dating back to April 2025. The malware is written in C++ and delivered in phishing attacks aimed at financial analysts specializing in the Taiwanese semiconductor industry.

Delivery

HealthKick was distributed using phishing emails impersonating investment research cooperation requests from fake financial consultancy companies. The email contained a PDF attachment redirecting to a ZIP archive uploaded to a legitimate file-sharing website. The ZIP archive included:

  • Loader – a legitimate binary vulnerable to DLL sideloading
  • libcef.dll – the malicious HealthKick DLL

In this instance, the exploited binary was adobe_licensing_wf_helper.exe, which loads libcef.dll from its current directory.

Persistence

Upon first execution, HealthKick creates a randomly named directory under C:\ProgramData\ and copies itself into it. Then, it creates a scheduled task [2]:

schtasks.exe /Create /TN "SystemHealthMonitor" /TR "\"malware_binary.exe" -run" /SC MINUTE /MO 5 /F

The -run command-line option is checked at the start of the malware's execution. If the flag isn't present, the malware recognizes that it's the first run, schedules the task and quits without doing anything else [3]. This is a sandbox evasion technique since automated sandboxes execute the malware only once.

C2 Protocol: Double Fake TLS

HealthKick's C2 traffic is wrapped in a fake TLS 1.2 header. However, the header is doubled. Furthermore, the payload is XOR-encoded with the hardcoded key mysecretkey [3].

[17 03 03 <LEN>] [17 03 03 <LEN>] [XOR-encoded payload]
^First TLS hdr ^Second TLS hdr ^actual content

Part 3: GOVERSHELL: A Family in Rapid Flux

GOVERSHELL refers to five distinct variants of backdoors developed from April to September 2025.

They have similar design philosophies: DLL sideloading through Tablacus Explorer, scheduling tasks, executing PowerShell commands, although the network stack code underwent a total rewrite almost every time there was a new variant. This tendency to rewrite the code in its entirety (instead of simply updating it) was considered circumstantial evidence of LLM-assisted development, an issue that will be examined later.

Common Architecture

All variants of GOVERSHELL (excluding the first variant, HealthKick) use Tablacus Explorer, a legitimate file manager, as their delivery mechanism through DLL sideloading. By launching the executable, the search order in Tablacus Explorer loads the lib\te64.dll file before any copy of the same file from the system

The malware establishes persistence via creating a scheduled task called MyGoTask (or UPnPHostUpdater in some later variants) via Windows COM interface instead of schtasks.exe command line utility:

Task name: MyGoTask
Trigger: Every 15 minutes
Command: <malware path> cuVn

The cuVn value is the flag required for the malware to activate its C2 functionality. The absence of this flag (first run) leads to installation of persistence and clean exit.

C2 Evolution: Variant 1 to 5

Within five months, from April to September 2025, GOVERSHELL had to rewrite its C2 logic almost from scratch five times [3].

Variant 1 (HealthKick) had a reverse TCP shell (CMD) to port 465 wrapped in double TLS 1.2 header due to what looks like an error, as we mentioned above.

In Variant 2, this issue was fixed; the malware also started encrypting the payload via AES-CFB with the key supersecretkey16 and executing commands via PowerShell, although the connection was still a persistent reverse shell.

Variant 3 abandoned the reverse shell concept and adopted a much more sophisticated HTTP poll/beacon scheme, where the malware periodically took commands to be executed using GET and sent answers via POST in JSON format.

Variant 4 used WebSocket instead of HTTP while implementing session key negotiation in AES-GCM and varying the master key for each compiled sample.

Finally, Variant 5 returned to HTTP but with configurable jitter and sleep periods.

This path goes from noisy, buggy reverse shell to stealthy, encrypted beacon in about five months.

LLM-Assisted Malware and Phishing Campaigns

It was observed by security analysts during the study of the GOVERSHELL campaigns that the attacker was likely assisted by LLMs during malware development and phishing email creation. Let’s look at the strong evidence.

The first type of evidence is a non-iterative malware code update pattern. Typically, human-made malware evolves iteratively, with bugs being fixed and new functionality being added to the existing base. The GOVERSHELL family, however, replaces its network stack every time with a new protocol. This is more characteristic of a prompt-and-answer approach, where the attacker repeatedly prompts the AI to create an implementation of a backdoor using X protocol.

Also, the Word document used as a decoy during the attack carried metadata showing that the document had been created using libraries typical for AI-generated .docx files.

Phishing emails were a different story. They were fluent in several languages (English, Chinese, Japanese, French, and German), but often contained inconsistent messages with the subject in one language and body in another. Finally, an email could simultaneously contain three distinct personas in sender name, friendly name, and message signature. OpenAI later confirmed that ChatGPT was used by the attacker to generate some parts of the campaign.

How Picus Simulates Voldemort, HealthKick, and GOVERSHELL Attacks?

We also strongly suggest simulating Voldemort, HealthKick, and GOVERSHELL Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Security Validation Platform. You can also test your defenses against hundreds of other malware variants, such as BRICKSTORM, VenomRAT, Chinotto, and Rustonotto, within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for the Voldemort, HealthKick, and GOVERSHELL Attacks:

Threat ID

Threat Name

Attack Module

66703

Voldemort Loader Email Threat

E-mail Infiltration

97485

Voldemort Loader Download Threat

Network Infiltration

61854

HealthKick Backdoor Malware Email Threat

E-mail Infiltration

42376

HealthKick Backdoor Malware Download Threat

Network Infiltration

73708

GOVERSHELL Backdoor Malware Download Threat

Network Infiltration

33964

GOVERSHELL Backdoor Malware Email Threat

E-mail Infiltration

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Security Validation Platform.

References

[1] “New Voldemort Malware Espionage Campaign,” Proofpoint. Accessed: May 19, 2026. [Online]. Available: https://www.proofpoint.com/us/blog/threat-insight/malware-must-not-be-named-suspected-espionage-campaign-delivers-voldemort

[2] “Phish and Chips: China-Aligned Espionage Actors Ramp Up Taiwan Semiconductor Industry Targeting,” Proofpoint. Accessed: May 19, 2026. [Online]. Available: https://www.proofpoint.com/us/blog/threat-insight/phish-china-aligned-espionage-actors-ramp-up-taiwan-semiconductor-targeting

[3] S. Adair, “APT Meets GPT: Targeted Operations with Untamed LLMs,” Volexity. Accessed: May 19, 2026. [Online]. Available: https://www.volexity.com/blog/2025/10/08/apt-meets-gpt-targeted-operations-with-untamed-llms/

 
Voldemort, HealthKick, and GOVERSHELL are three malware families linked to Chinese state-sponsored espionage operations that surfaced between mid-2024 and late 2025. These toolkits were used in targeted attacks against Taiwanese semiconductor manufacturers and international think tanks. All three families are distributed via spear-phishing emails and abuse the DLL sideloading technique to compromise victim systems.
Voldemort uses Google Sheets as its C2 server, a highly unusual approach that allows attackers to blend malicious traffic with legitimate Google Workspace activity. The malware sends traffic to sheets.googleapis.com on port 443, making it virtually impossible to distinguish from regular enterprise Google traffic in network logs. Victim registration and command polling both occur through cells in a specific Google Sheet.
HealthKick, discovered in April 2025, is actually the first version of the GOVERSHELL malware family, also known as GOVERSHELL v1. Written in C++, it was later replaced by a fully redesigned GOVERSHELL v2 written in Go. Altogether, five different versions of GOVERSHELL exist, each using different C2 communication protocols and encryption algorithms.
From April to September 2025, GOVERSHELL rewrote its C2 logic five times. Variant 1 used a reverse TCP shell with double TLS headers, Variant 2 added AES-CFB encryption and PowerShell execution, Variant 3 adopted HTTP poll/beacon, Variant 4 used WebSocket with AES-GCM session keys, and Variant 5 returned to HTTP with configurable jitter and sleep periods.
Two key indicators point to LLM involvement. The non-iterative code update pattern in GOVERSHELL, which completely replaces its network stack with each version instead of evolving existing code, resembles a prompt-and-answer approach. Additionally, decoy Word documents contained metadata typical of AI-generated files, and OpenAI confirmed that ChatGPT was used by the attacker to generate parts of the campaign.
Voldemort's DLL sideloaded payload begins with a 5 to 10 minute sleep, causing most automated sandboxes to time out before detecting malicious network activity. HealthKick uses a flag check on first execution, scheduling its persistence task and quitting silently if the -run command-line option is absent, since automated sandboxes typically execute the malware only once.
The Picus Security Validation Platform validates organizations' defenses against Voldemort, HealthKick, and GOVERSHELL malware families. The Picus Threat Library includes specific threats covering email infiltration and network infiltration scenarios for each family.

 

 
Voldemort, HealthKick, and GOVERSHELL are three malware families linked to Chinese state-sponsored espionage operations that surfaced between mid-2024 and late 2025. These toolkits were used in targeted attacks against Taiwanese semiconductor manufacturers and international think tanks. All three families are distributed via spear-phishing emails and abuse the DLL sideloading technique to compromise victim systems.
Voldemort uses Google Sheets as its C2 server, a highly unusual approach that allows attackers to blend malicious traffic with legitimate Google Workspace activity. The malware sends traffic to sheets.googleapis.com on port 443, making it virtually impossible to distinguish from regular enterprise Google traffic in network logs. Victim registration and command polling both occur through cells in a specific Google Sheet.
HealthKick, discovered in April 2025, is actually the first version of the GOVERSHELL malware family, also known as GOVERSHELL v1. Written in C++, it was later replaced by a fully redesigned GOVERSHELL v2 written in Go. Altogether, five different versions of GOVERSHELL exist, each using different C2 communication protocols and encryption algorithms.
From April to September 2025, GOVERSHELL rewrote its C2 logic five times. Variant 1 used a reverse TCP shell with double TLS headers, Variant 2 added AES-CFB encryption and PowerShell execution, Variant 3 adopted HTTP poll/beacon, Variant 4 used WebSocket with AES-GCM session keys, and Variant 5 returned to HTTP with configurable jitter and sleep periods.
Two key indicators point to LLM involvement. The non-iterative code update pattern in GOVERSHELL, which completely replaces its network stack with each version instead of evolving existing code, resembles a prompt-and-answer approach. Additionally, decoy Word documents contained metadata typical of AI-generated files, and OpenAI confirmed that ChatGPT was used by the attacker to generate parts of the campaign.
Voldemort's DLL sideloaded payload begins with a 5 to 10 minute sleep, causing most automated sandboxes to time out before detecting malicious network activity. HealthKick uses a flag check on first execution, scheduling its persistence task and quitting silently if the -run command-line option is absent, since automated sandboxes typically execute the malware only once.
The Picus Security Validation Platform validates organizations' defenses against Voldemort, HealthKick, and GOVERSHELL malware families. The Picus Threat Library includes specific threats covering email infiltration and network infiltration scenarios for each family.

Table of Contents

Ready to start? Request a demo