GoldenJackal is a cyber espionage group that targets government and diplomatic entities in Europe, the Middle East, and South Asia. Active since at least 2019, the group is little known and has only been publicly described once, by Kaspersky, in 2023. The group's known toolset includes several implants written in C#, all of them used for espionage. In 2024, we have observed GoldenJackal actively deploying a new, highly modular toolset in a government organization in Europe. This toolset provides a wide set of capabilities for targeting and persisting in compromised networks, as well as for reaching air-gapped systems. Victimized hosts are given different roles in the local network, from collecting interesting information to further processing the information; distributing files, configurations, and commands to other systems; or exfiltrating files. The modular nature of its operations shows how the group has gone to great lengths to conceal its activities and hide the true origin of the attacks. In this session we publicly describe GoldenJackal's new tools for the first time. Based on analysis of the new toolset and observation of other attacks using the group's publicly described tools, we were able to time travel back to August 2019 to discover an earlier toolset used by the group. This is one of GoldenJackal's most sophisticated toolsets, designed – yet again – to target and compromise air-gapped systems. Shrouded in mystery, we've only observed these custom tools once, and never again, in a South Asian embassy in Belarus. In this session, we also describe these tools for the first time. While attribution of GoldenJackal activities to a particular nation state is quite elusive, we provide some insight based on the observed attacks. Our goal for this presentation is to build on public knowledge of the group, hopefully guiding other researchers to uncover more pieces of the puzzle.