GOLD SOUTHFIELD

APT / StateG0115
Techniques (MITRE ATT&CK)9
SourceMITRE ATT&CK
0
Also known as:Pinchy Spider

Vexday analysis

GOLD SOUTHFIELD (também conhecido como Pinchy Spider; identificador MITRE ATT&CK G0115) é um grupo com motivação financeira ativo desde pelo menos 2018, responsável pela operação do ransomware REvil no modelo Ransomware-as-a-Service (RaaS). O grupo fornece infraestrutura de back-end para afiliados recrutados em fóruns clandestinos, viabilizando implantações de alto valor. A partir do início de 2020, passou a adotar a prática de exfiltração de dados combinada à extorsão, ameaçando divulgar publicamente as informações das vítimas caso o resgate não fosse pago. Ao grupo são atribuídas 9 técnicas documentadas no MITRE ATT&CK e 2 CVEs de exploração conhecida.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity36
Impact: High
T1190T1059.001T1133ENTRYInitial accessExploitPublic-Facing App…EXECExecutionPowerShellPERSPersistenceExternal RemoteServicesCOLLCollectionScreen Capture

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 9

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 2

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 26

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

sha256_hash5ac8a9a6e2c82f5d99ff071df7d0c2d11e46bbf62b2f7f19d492b9a71ffca256ConnectWisemalwarebazaar
sha256_hash61366dc491bce133ceaeb4f1e93250b85431f99e9b5411ebea36c3f25a9b7467ConnectWisemalwarebazaar
sha256_hashc7ddbfb63ca023be66b0cd6f182ae0fe8c926e67ea686d5cb5d1c13e6df3b4feConnectWisemalwarebazaar
sha256_hashad699b741b7526faaf96e8d7f9666f0780d091b24392624f3fe392970f4d157cConnectWisemalwarebazaar
sha256_hash601ebaecf6ea1a805b788ca07d202a1e5301f09882a6464ff35203a17020c248ConnectWisemalwarebazaar
sha256_hash7ace2517f867d28a2e341cd9a9caad287630d3e93b2ae6ecd3fc027dd55ff8dbConnectWisemalwarebazaar
sha256_hashe4159cbaea5881ac72afaa239265f801d1a8d079cf87275e94aaea2f8cc1dedaConnectWisemalwarebazaar
sha256_hash0a16de6fe251f0afe91560e7193b0e7b9cc1ac80dfe714ea43f888d7ab1d7d2aConnectWisemalwarebazaar
sha256_hash031dcce29761f42a1b40767b358b18d70e8745b233dd21f6f673b7b45b5a60b4ConnectWisemalwarebazaar
sha256_hash0eebdbd4fb46d04352fa09ce96cb34991bd5950cf8a8be9e403ddb1d485a870aConnectWisemalwarebazaar
sha256_hashf1faad45e97dea697036ef3fc141ee1b8259a80f773da7927f9c8491481c3c7dConnectWisemalwarebazaar
sha256_hash56cbbf481154a08fbfec54484ca04f6045dfe0e2fc082c6249592ecc4aaf1c5eConnectWisemalwarebazaar
sha256_hashfda5556e3fa55664509ab396469d00939b0ac6260d01c8cdfbde999ee3a9d0abConnectWisemalwarebazaar
sha256_hashbbdb4e10ba2e085d83eeb97b10efc6f446cf040cfd10deb0ee48c375f4805953ConnectWisemalwarebazaar
sha256_hash16d76fb73e844e7ae13081b614f4b7449d4f020246189bfd6d77585d33a55a71ConnectWisemalwarebazaar
sha256_hash732dfed9c6d0fbdfd29addfb4d3981dd4f50bbb1417bd397ad42787a21b7558aConnectWisemalwarebazaar
sha256_hash97219eed1eda6a12d672138da9c9c540e95be415d227fd81c6933eb1b81f7160ConnectWisemalwarebazaar
sha256_hash1c581a5bcc6a4fb4ecb9d6151c9c88adfe678d3771fdd1accf9820152064f0c2ConnectWisemalwarebazaar
sha256_hash44b6d6bbd97152d4e7cd25ed49bde0f8a1c5d30c241d99c4a34f66cec3f28e2fConnectWisemalwarebazaar
sha256_hash6f2139d68bc0222b441fadeb6f484650ee7192aceea86c5399749b279898abd0ConnectWisemalwarebazaar
sha256_hash2b5f7211a6c98dc9302023024cf7e11e5360314160a6b291f74350eeb46c072dConnectWisemalwarebazaar
sha256_hash0b3a0e6bf514f9baecd9f26cdbeb74afc455666d0d41db4b8673f7a98cd855cfConnectWisemalwarebazaar
sha256_hashcd68d01fe8e57890fcbbe66833a8416981feda4d79148a661692fa364db66738ConnectWisemalwarebazaar
sha256_hash24cf9f32c1e3ebec5e810a865ad4acdcd28669d4b548929c8e4a962d77e44b1bConnectWisemalwarebazaar
sha256_hashf8cd736a531c65cce00a01fab875cb2cc350b4561e6eaa643fb46d1b62cb3ba7ConnectWisemalwarebazaar
sha256_hash39030298332d4ad0b3b3cb987a4bb9501f19d8ba48b393f187cf560db6b60a79ConnectWisemalwarebazaar

GOLD SOUTHFIELD uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →