Trusted Design

GOLD SOUTHFIELD

アクターID: G0115

· MITRE Pageへのリンク

脅威アクターの詳細

GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.(Citation: Secureworks REvil September 2019)(Citation: Secureworks GandCrab and REvil September 2019)(Citation: Secureworks GOLD SOUTHFIELD)(Citation: CrowdStrike Evolution of Pinchy Spider July 2021)

脅威アクターの別名・別称

GOLD SOUTHFIELD
Pinchy Spider

利用した攻撃手法

関連するCVE (攻撃手法に関連)

Actor – Pulse グラフ


← 脅威アクター一覧に戻る