---
title: "Experts Say China Hid Spyware in Mandatory Tax Software"
description: "Security researchers discovered that Golden Tax Invoicing, which is required for doing business in China, contains spyware that grants backdoor access."
date: "2020-07-14"
modified: "2020-07-14"
authors:
  - name: "Dan Robitzski"
    link: "https://futurism.com/authors/danrobitzski"
url: "https://futurism.com/the-byte/china-hid-spyware-mandatory-tax-software"
categories:
  - "Science & Energy"
tags:
  - "china"
  - "financial"
  - "spyware"
  - "the digest"
---

# Experts Say China Hid Spyware in Mandatory Tax Software

![Security researchers discovered that Golden Tax Invoicing, which is required for doing business in China, contains spyware that grants backdoor access.](<https://futurism.com/wp-content/uploads/2020/07/china-hid-spyware-mandatory-tax-software.jpg>)
*\<em\>Image: Victor Tangermann\</em\>*

## Mandatory Backdoor

Any company doing business in China is required to file for taxes using software called Golden Tax Invoicing. And now, security researchers have an idea why the Chinese government likes it so much: they say it's riddled [with spyware](<https://futurism.com/the-byte/china-cyberweapons-nsa-us-allies>).

Installing Golden Tax Invoicing infects computers with spyware called GoldenHelper, *[Ars Technica](<https://arstechnica.com/information-technology/2020/07/malware-stashed-in-china-mandated-software-is-more-extensive-than-thought/>)*[ reports](<https://arstechnica.com/information-technology/2020/07/malware-stashed-in-china-mandated-software-is-more-extensive-than-thought/>), which essentially grants backdoor access into the system. [First revealed](<https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/goldenspy-chapter-4-goldenhelper-malware-embedded-in-official-golden-tax-software/>) by the cybersecurity firm Trustwave, the sophisticated malware campaign reveals a troublingly-widespread level of [digital infiltration](<https://futurism.com/us-officials-chinese-hackers-targeting-vaccine-research>).

## Take Two

Trustwave revealed the Golden Tax spyware just three weeks after uncovering a similar malware campaign, GoldenSpy, which also hid in Golden Tax, *Ars* reports. The two programs are functionally similar and sneak behind a computer's security systems using the same mechanisms.

GoldenSpy seemed to disappear after it was outed. But it's not clear whether the new spyware was meant to replace it or if it had already existed alongside GoldenSpy.

## Missing Piece

Trustwave's investigation is still ongoing: *Ars* reports that the company's researchers have yet to find GoldenHelper's actual payload, which they say is called "taxver.exe."

So that means that it's not entirely clear what information it can take from an infected system — only that a big problem is out there.

**READ MORE:** [Malware stashed in China-mandated software is more extensive than thought](<https://arstechnica.com/information-technology/2020/07/malware-stashed-in-china-mandated-software-is-more-extensive-than-thought/>) \[*Ars Technica*\]

**More on hacking:** *[US Officials: Chinese Hackers Are Targeting Vaccine Research](<https://futurism.com/us-officials-chinese-hackers-targeting-vaccine-research>)*

## Author
Dan Robitzki is a senior reporter for Futurism, where he likes to cover AI, tech ethics, and medicine. He spends his extra time fencing and streaming games from Los Angeles, California.

### Author social links  
[Twitter](<https://x.com/danrobitzski>)