GOLD SOUTHFIELD

APT / StateG0115 ↗
Techniques (MITRE ATT&CK)9
SourceMITRE ATT&CK
0
Also known as:Pinchy Spider

About the group

GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity36
Impact: High
T1190T1059.001T1133ENTRYInitial accessExploitPublic-Facing App…EXECExecutionPowerShellPERSPersistenceExternal RemoteServicesCOLLCollectionScreen Capture

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 9

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 2

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 72

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

sha256_hashde201c3437586ab3684f3ec225b5eca89eb40b73d2206297dbb4985cc9d5d80dConnectWisemalwarebazaar
sha256_hash0e38556099f10acb59a46f5876dedaa2d8aac0cad7d65f02d900a3275f74e604ConnectWisemalwarebazaar
sha256_hash98f53a1753eabfccba6282f8ee0ba50bfe201c8b6389304ab0f4f20b1958d953ConnectWisemalwarebazaar
sha256_hash21532a91d4fc7b6d3f5d89c1d24dfaf5dd40b7101d8afba8be396d300779eb6aConnectWisemalwarebazaar
sha256_hash03952a4002a5b73fca77e4acab7160aa7438607b2f585b67e99750b7a6bb0547ConnectWisemalwarebazaar
sha256_hasheb104349ede33de0d093d2adfca3a778fc5ef34cc3a0c7b1d6839431968e738cConnectWisemalwarebazaar
sha256_hash9d1eaecbdf2df0cdf931c2c8ff81e1efba5eb3427da252232c748ff191cf2301ConnectWisemalwarebazaar
sha256_hash91a7700458df1c2ec3d97f9a15633c87ac7c40a758cdb61f9a3700075f98bcd0ConnectWisemalwarebazaar
sha256_hash554cde31c2d443a18d0a4ae081bb535f690a3d3b60ce217b425196ed2c53fecbConnectWisemalwarebazaar
sha256_hasha8d56778dbe36e9c911d536bfdcb0fdf384cd3f8fb5b625bb7d242f5896691deConnectWisemalwarebazaar
sha256_hash378cfed93e93094c5044aea2894454222beaa0ca92fb2ef1a2ce6e37df36eebcConnectWisemalwarebazaar
sha256_hash33a7b824bc687c330c33c1870a9243d2f527c43d63a1fa95b3ad02c12dfe5f81ConnectWisemalwarebazaar
sha256_hashb1a1aa3898af536d58e251a42ad1c54f072a1f2e62db0e5b379c69e2db8fc770ConnectWisemalwarebazaar
sha256_hash65f984e41b45a5563cc41922e0cae530a3175bca19b33c9406ac7276adea30bdConnectWisemalwarebazaar
sha256_hash3fcc07382f02047b246345315e955a028acb1f35bc4ff97e03584eee04cc6ee7ConnectWisemalwarebazaar
sha256_hash434ffec81e6c1be4873754fa5854fd6c5b3d387a4b9f2119a7bfec8bbe181d9fConnectWisemalwarebazaar
sha256_hashede450e3c9f6bdfc7de2fbda91eac908510f970a1e1e17bebb8fb9ecd1721342ConnectWisemalwarebazaar
sha256_hash893c62949e0430b65f75f2b28b565fa0b056dfc9dea24ae795577788fedac3f6ConnectWisemalwarebazaar
sha256_hashad69bdba7b5725e5c5d63025f8625697aaa27e7b817eb1e57e7c7555e4bdfdccConnectWisemalwarebazaar
sha256_hash5ac7b697d01dd22359ecfb4687b1e21ee09f3fe9aaca8e571565717ae8af3bd5ConnectWisemalwarebazaar
sha256_hasha955dad7a3e578f1fc0e6e956d168bc395e940e7e9535049e50aeb296483607bConnectWisemalwarebazaar
sha256_hash7ef03054d3a602d418a382b00f10970148ce87d107f7d06e9fa5da71c8e4d3daConnectWisemalwarebazaar
sha256_hashed6585c0ce967cfeaf497b8f06c15591b00110073686c73bec7ff05abdead620ConnectWisemalwarebazaar
sha256_hash92ad27531df11d88a313573da42427bcbb3e6cef9bbf9e84202e68a7368afd1bConnectWisemalwarebazaar
sha256_hash28d65f871d2b7aabc8fe8a13dfca6a48b2d87a49e80773d9e62cbb955beb0761ConnectWisemalwarebazaar
sha256_hash0142e425a1d24fef352524cfc26a83579e449894de3694901faca802af966b5fConnectWisemalwarebazaar
sha256_hash6374eb353f02c7b26e00697a32f4a4f613402ca0296f5f10afdb3243f729c1b9ConnectWisemalwarebazaar
sha256_hash4fe63644cb31e88f53069f30cb4d3690f2bdc0ca2734892741d3cafbd0380bfaConnectWisemalwarebazaar
sha256_hash40a49b61a61a99c570b6c1e01f437dac7f8e0c7ad8cdfba407884cec37ba8b1bConnectWisemalwarebazaar
sha256_hash0561af45f46c8ecae3b1a7f90b566896bb6edd9e9d0a516d80ecd095a1be142bConnectWisemalwarebazaar

+72 indicators in total. See them all on the IOCs page.

GOLD SOUTHFIELD uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →