Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOLD REBELLION

Also known as: WANDERING SPIDER, White Dev 115, Dark Scorpius, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, tracked as, CVE-2026-64638, CVE-2026-64564, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork

Description

GOLD REBELLION emerged in early 2022 with the first victim leak published in April of that year, and it has maintained a high output of ransom demands—around fifteen per month historically—showing an aggressive commercial approach. Technical analyses indicate the group was behind Black Basta from at least February 2022 and shares similarities with former Conti affiliates. While the organization has not publicly advertised affiliation programs, its tactics suggest multiple contributors collaborating on the ransomware effort. The attackers employ a layered attack chain that begins with spear‑phishing attachments (malicious Microsoft Word documents) or watering‑hole compromises of legitimate websites. Once inside, they exploit CVE‑2026‑64638, CVE‑2026‑64564, TeamCity CVE‑2023‑42793 and other software vulnerabilities to gain initial access and elevate privileges. They deploy backdoors such as IRONHALO and ELMER, leverage remote assistance tools like TeamViewer, AnyDesk or Remote Desktop Protocol (RDP) for lateral movement, and use PsExec for execution. Data exfiltration is frequently conducted via cloud sync services Rclone or MegaSync. In addition to ransomware distribution, the group demonstrates advanced persistence techniques—batch files that delete their own artifacts, disabling anti‐virus software, and periodic updates of its toolset. Their social engineering campaigns mimic IT support staff on Microsoft Teams, adding a deceptive layer that often involves remote control utilities like Quick Assist.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Energy
Aerospace
Media
Education
Information technology
Healthcare
Pharmaceutical
Manufacturing
Maritime
Think tank
Chemical
Entertainment
Hospitality
Mining
Nuclear
Gaming
Construction
Legal services
Retail
Transportation
Food agriculture

Targeted Countries / Regions

US
CN
GB
IN
JP
KR
DE
RU
IR
CA
FR
SA
TW
IL
TR
AU
PK
KZ
ES
UA
PL
SG
VN
NL
BR
IT
BY
AE
IQ
MX
RO
SY
AZ
EG
LB

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

GOLD REBELLION is a financially motivated threat group that also engages in espionage, operating the Black Basta ransomware under a name‑and‑shame strategy. It targets a broad spectrum of sectors—including government, defense, telecommunications and heavy industry—across many countries using sophisticated spear‑phishing, watering‑hole and CVE exploitation techniques. The group adapts its delivery vectors over time, moving from Qakbot distribution to DarkGate, Pikabot and MSSP infiltration, while continuously exploiting new vulnerabilities.

Goals & Targeting

GOLD REBELLION pursues dual objectives: generating revenue through ransomware extortion while simultaneously collecting strategic data from high‑value targets such as defense contractors, energy firms and diplomatic entities. The actor explicitly seeks sensitive information from governments, military organizations, telecom operators, heavy industry manufacturers and research institutions across more than 30 countries. Its operational focus balances profitable blackmail with intelligence gathering that can potentially be leveraged for geopolitical advantage.

Enhanced Description

Key Capabilities

  • "Spear‑phishing with malicious Microsoft Word documents"
  • "Watering‑hole attacks on legitimate websites"
  • "Exploitation of known CVE vulnerabilities (e.g., CVE‑2026‑64638, CVE‑2026‑64564, TeamCity CVE‑2023‑42793) for initial access and privilege escalation"
  • "Deployment and use of backdoors such as IRONHALO and ELMER"
  • "Leveraging legitimate remote support tools (TeamViewer, AnyDesk, Quick Assist) for lateral movement and execution"
  • "Use of RDP and PsExec to spread within networks"
  • "Distribution of Black Basta ransomware and associated payloads"
  • "Data exfiltration via cloud sync services (Rclone, MegaSync)"
  • "Defense evasion through batching, anti‑virus disablement, and self‑deletion routines"

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation
Persistence
Lateral Movement
Defense Evasion
Exfiltration
Impact

ATT&CK Techniques

T1566.002
T1190
T1204
T1068
T1021
T1071
T1059

Software / Tooling

"Black Basta ransomware"
"SystemBC backconnect malware"
"Nefilim"
"IRONHALO"
"ELMER"
"MiniDuke/SeaDuke/CozyDuke variants"
"TeamViewer"
"AnyDesk"
"Quick Assist"
"PsExec"
"RDP"
"Rclone"
"MegaSync"
"BackConfig"
"Infostealer"
"TigerRAT"

Campaigns & Victims

Since its first public victim leak in April 2022, GOLD REBELLION has maintained a consistent ransomware threat model, typically revealing approximately fifteen victims each month. Early operations relied heavily on Qakbot as an initial access vector until its August‑2023 takedown, after which the group shifted to DarkGate and Pikabot, and even exploited MSSP footholds. In 2024 the attackers were observed exploiting a vulnerability in SonicWall VPN devices (CVE‑2026‑64638) and increasingly using social engineering via Microsoft Teams to masquerade as IT support for remote management tools. Their campaigns are opportunistic yet frequent, targeting high‑profile sectors worldwide with repeated use of the same backdoor families and exfiltration mechanisms.

IOC Patterns

  • "CVE exploitation"
  • "Malicious Microsoft Word document attachments"
  • "Watering-hole website URLs"
  • "Backdoor domain names/hosts for IRONHALO or ELMER"
  • "Remote support tool domains (TeamViewer, AnyDesk)"

Recommended Actions

  • "Patch all known CVE vulnerabilities promptly, especially CVE‑2026‑64638 and CVE‑2026‑64564."
  • "Block or quarantine suspicious Microsoft Word attachments from unknown senders and enforce attachment scanning."
  • "Implement web filtering and threat intelligence blocks to detect compromised legitimate sites used for watering holes."
  • "Enable multi‑factor authentication (MFA) across all services, particularly on remote desktop protocols and Teams channels."
  • "Restrict the use of third‑party remote support applications such as TeamViewer, AnyDesk, or Quick Assist unless strictly controlled; monitor usage logs."
  • "Deploy endpoint detection to flag installation of backdoor tools like IRONHALO, ELMER, Nefilim, and TigerRAT."
  • "Maintain up‑to‑date patching for critical software (TeamCity, SonicWall VPN, etc.) and conduct regular vulnerability scanning."

Suggested Tags

"APT"
"phishing"
"watering hole"
"CVE exploitation"
"Microsoft Teams"
"China-based"
"government targeting"
"military contractor"
"heavy-industry-targeted"
"defense-technology-targeted"
"diplomacy-targeted"
"spear‐phishing"
"teamviewer-use"
"infostealer"
"tigerrat"

Confidence Assessment

The dataset draws from multiple reputable sources (CTU, SentinelOne, Microsoft Security Blog), giving the analysis a moderate level of confidence. While there is strong evidence for the group’s use of backdoors, ransomware, and CVE exploitation, some associations—such as ties to GOLD NIAGARA/FIN7 or use of Qakbot—are inferred rather than directly observed in independent reports. Further confirmation of tool attribution and operational overlap would increase confidence.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

Intel Summary

7

Techniques

56

Tools

0

Campaigns

46

IOCs

0

Observed Data

5

Tactics

Tags

Ransomware
Critical Infrastructure
Data Exfiltration
Name-and-shame ransomware
Financially motivated cybercrime
APT-like group
Sectors: Multiple
"APT"
"phishing"
"watering hole"
"CVE exploitation"
"Microsoft Teams"
"China-based"
"government targeting"
"military contractor"
"heavy-industry-targeted"
"defense-technology-targeted"
"diplomacy-targeted"
"spear‐phishing"
"teamviewer-use"
"infostealer"
"tigerrat"

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.