ATT&CKGroupsGOLD SOUTHFIELD

GOLD SOUTHFIELD

G0115

Threat group.View on attack.mitre.org

About this group

GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1027.010
Command Obfuscation

GOLD SOUTHFIELD has executed base64 encoded PowerShell scripts on compromised hosts.

T1059.001
PowerShell

GOLD SOUTHFIELD has staged and executed PowerShell scripts on compromised hosts.

T1113
Screen Capture

GOLD SOUTHFIELD has used the remote monitoring and management tool ConnectWise to obtain screen captures from victim's machines.

T1133
External Remote Services

GOLD SOUTHFIELD has used publicly-accessible RDP and remote management and monitoring (RMM) servers to gain access to victim machines.

T1190
Exploit Public-Facing Application

GOLD SOUTHFIELD has exploited Oracle WebLogic vulnerabilities for initial compromise.

T1195.002
Compromise Software Supply Chain

GOLD SOUTHFIELD has distributed ransomware by backdooring software installers via a strategic web compromise of the site hosting Italian WinRAR.

T1199
Trusted Relationship

GOLD SOUTHFIELD has breached Managed Service Providers (MSP's) to deliver malware to MSP customers.

T1219
Remote Access Tools

GOLD SOUTHFIELD has used the cloud-based remote management and monitoring tool "ConnectWise Control" to deploy REvil.

T1566
Phishing

GOLD SOUTHFIELD has conducted malicious spam (malspam) campaigns to gain access to victim's machines.

Software2

Campaigns0

None recorded.

References4

  1. CrowdStrike Evolution of Pinchy Spider July 2021 Open source
    Meyers, Adam. (2021, July 6). The Evolution of PINCHY SPIDER from GandCrab to REvil. Retrieved March 28, 2023.
  2. Secureworks GOLD SOUTHFIELD Open source
    Secureworks. (n.d.). GOLD SOUTHFIELD. Retrieved October 6, 2020.
  3. Secureworks GandCrab and REvil September 2019 Open source
    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.
  4. Secureworks REvil September 2019 Open source
    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.