GOLD SOUTHFIELD

MITRE ATT&CK: G0115 View on attack.mitre.org

Aliases: Pinchy Spider, GOLD SOUTHFIELD

First seen
2018-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
expert
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:56:12

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications education-and-nonprofits government-and-public-sector

Context

GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.

Detection coverage

  • 17 YARA rules
  • 282 Sigma rules

Malware & tools used

  • Trusted Relationship (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Screen Capture (attack-pattern)
  • Remote Access Tools (attack-pattern)
  • Compromise Software Supply Chain (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • External Remote Services (attack-pattern)
  • PowerShell (attack-pattern)
  • Phishing (attack-pattern)
  • ConnectWise (malware)
  • REvil (malware)

Reports & references

  • secureworks.com — How Cyber Adversaries Are Adapting To Exploit The Global Pandemic (report)
  • secureworks.com — Gold Southfield (report)
  • secureworks.com — Revil Sodinokibi Ransomware (report)
  • secureworks.com — Revil The Gandcrab Connection (report)
  • MITRE ATT&CK — G0115 (report)
  • CrowdStrike — The Evolution Of Revil Ransomware And Pinchy Spider (report)
  • secureworks.com — Gold Southfield (report)

External references