Also known as: WANDERING SPIDER, White Dev 115, Dark Scorpius, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, tracked as, CVE-2026-64638, CVE-2026-64564, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork
GOLD REBELLION emerged in early 2022 with the first victim leak published in April of that year, and it has maintained a high output of ransom demands—around fifteen per month historically—showing an aggressive commercial approach. Technical analyses indicate the group was behind Black Basta from at least February 2022 and shares similarities with former Conti affiliates. While the organization has not publicly advertised affiliation programs, its tactics suggest multiple contributors collaborating on the ransomware effort. The attackers employ a layered attack chain that begins with spear‑phishing attachments (malicious Microsoft Word documents) or watering‑hole compromises of legitimate websites. Once inside, they exploit CVE‑2026‑64638, CVE‑2026‑64564, TeamCity CVE‑2023‑42793 and other software vulnerabilities to gain initial access and elevate privileges. They deploy backdoors such as IRONHALO and ELMER, leverage remote assistance tools like TeamViewer, AnyDesk or Remote Desktop Protocol (RDP) for lateral movement, and use PsExec for execution. Data exfiltration is frequently conducted via cloud sync services Rclone or MegaSync. In addition to ransomware distribution, the group demonstrates advanced persistence techniques—batch files that delete their own artifacts, disabling anti‐virus software, and periodic updates of its toolset. Their social engineering campaigns mimic IT support staff on Microsoft Teams, adding a deceptive layer that often involves remote control utilities like Quick Assist.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GOLD REBELLION is a financially motivated threat group that also engages in espionage, operating the Black Basta ransomware under a name‑and‑shame strategy. It targets a broad spectrum of sectors—including government, defense, telecommunications and heavy industry—across many countries using sophisticated spear‑phishing, watering‑hole and CVE exploitation techniques. The group adapts its delivery vectors over time, moving from Qakbot distribution to DarkGate, Pikabot and MSSP infiltration, while continuously exploiting new vulnerabilities.
Goals & Targeting
GOLD REBELLION pursues dual objectives: generating revenue through ransomware extortion while simultaneously collecting strategic data from high‑value targets such as defense contractors, energy firms and diplomatic entities. The actor explicitly seeks sensitive information from governments, military organizations, telecom operators, heavy industry manufacturers and research institutions across more than 30 countries. Its operational focus balances profitable blackmail with intelligence gathering that can potentially be leveraged for geopolitical advantage.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first public victim leak in April 2022, GOLD REBELLION has maintained a consistent ransomware threat model, typically revealing approximately fifteen victims each month. Early operations relied heavily on Qakbot as an initial access vector until its August‑2023 takedown, after which the group shifted to DarkGate and Pikabot, and even exploited MSSP footholds. In 2024 the attackers were observed exploiting a vulnerability in SonicWall VPN devices (CVE‑2026‑64638) and increasingly using social engineering via Microsoft Teams to masquerade as IT support for remote management tools. Their campaigns are opportunistic yet frequent, targeting high‑profile sectors worldwide with repeated use of the same backdoor families and exfiltration mechanisms.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The dataset draws from multiple reputable sources (CTU, SentinelOne, Microsoft Security Blog), giving the analysis a moderate level of confidence. While there is strong evidence for the group’s use of backdoors, ransomware, and CVE exploitation, some associations—such as ties to GOLD NIAGARA/FIN7 or use of Qakbot—are inferred rather than directly observed in independent reports. Further confirmation of tool attribution and operational overlap would increase confidence.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
56
Tools
0
Campaigns
46
IOCs
0
Observed Data
5
Tactics