GOLD SOUTHFIELD
MITRE ATT&CK: G0115 View on attack.mitre.org
Aliases: Pinchy Spider, GOLD SOUTHFIELD
- First seen
- 2018-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- expert
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:56:12
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications education-and-nonprofits government-and-public-sector
Context
GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.
Detection coverage
- 17 YARA rules
- 282 Sigma rules
Malware & tools used
- Trusted Relationship (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Screen Capture (attack-pattern)
- Remote Access Tools (attack-pattern)
- Compromise Software Supply Chain (attack-pattern)
- Command Obfuscation (attack-pattern)
- External Remote Services (attack-pattern)
- PowerShell (attack-pattern)
- Phishing (attack-pattern)
- ConnectWise (malware)
- REvil (malware)
Reports & references
- secureworks.com — How Cyber Adversaries Are Adapting To Exploit The Global Pandemic (report)
- secureworks.com — Gold Southfield (report)
- secureworks.com — Revil Sodinokibi Ransomware (report)
- secureworks.com — Revil The Gandcrab Connection (report)
- MITRE ATT&CK — G0115 (report)
- CrowdStrike — The Evolution Of Revil Ransomware And Pinchy Spider (report)
- secureworks.com — Gold Southfield (report)