Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOLD SOUTHFIELD

Also known as: Pinchy Spider

Description

GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.(Citation: Secureworks REvil September 2019)(Citation: Secureworks GandCrab and REvil September 2019)(Citation: Secureworks GOLD SOUTHFIELD)(Citation: CrowdStrike Evolution of Pinchy Spider July 2021)

AI Analysis

· 1 week ago

Executive Summary

GOLD SOUTHFIELD, also known as Pinchy Spider, is a financially motivated threat actor that operates the REvil Ransomware-as-a-Service (RaaS) platform since at least 2018. Initially focused on traditional ransomware, they evolved by leveraging stolen data to extort victims beyond payment demands in early 2020. Their strategic shift to data theft and extortion significantly increases the pressure on targeted organizations.

Goals & Targeting

GOLD SOUTHFIELD primarily seeks financial gain through ransomware campaigns and data extortion, targeting sectors such as healthcare, education, and critical infrastructure. Their focus on these sectors is driven by the potential for higher ransoms, availability of sensitive data, and the victims' desire to avoid public exposure of stolen information. The group's strategic choice of targets reflects a deep understanding of which industries are most vulnerable to both financial pressure and reputational damage.

Enhanced Description

GOLD SOUTHFIELD is a sophisticated threat actor that operates the REvil RaaS platform, enabling affiliates to execute high-value ransomware attacks. By recruiting affiliates through underground forums, the group has expanded its operational scope, focusing on both traditional ransomware deployment and data theft followed by extortion. Their evolution in tactics, particularly their emphasis on stealing sensitive data and threatening public leaks, highlights a shift towards more damaging and high-stakes operations. This approach not only increases financial gains but also raises the stakes for victims who may face significant reputational damage alongside financial losses. The group's ability to adapt their tactics underscores their strategic ingenuity and operational resilience in the cybercrime landscape.

Key Capabilities

  • REvil Ransomware platform
  • Spear phishing campaigns
  • Data extortion tactics
  • Affiliate recruitment for attacks
  • Sophisticated operational infrastructure

MITRE ATT&CK Tactics

Ransomware
Data Exfiltration
Initial Access
Defense Evasion

ATT&CK Techniques

T1566.002
T1059.001
T1219
T1238.001
T1565

Software / Tooling

REvil Ransomware
Spear Phishing Tools
Malicious Email Payloads

Campaigns & Victims

GOLD SOUTHFIELD's campaigns typically involve targeted phishing attacks, followed by ransomware deployment and data exfiltration. They have been observed targeting organizations with robust encryption and a focus on sectors with high data sensitivity. Notable past operations include REvil-related incidents where victims were threatened with data leaks if ransoms weren't paid.

IOC Patterns

  • Spear phishing emails with malicious attachments
  • REvil ransomware signatures in network traffic
  • C2 communications via encrypted channels
  • Use of compromised accounts for lateral movement

Recommended Actions

  • Implement multi-layered email filtering to detect and block spear-phishing attempts.
  • Monitor for unusual network activity indicative of REvil ransomware payloads.
  • Enhance incident response plans to quickly isolate and contain potential breaches.
  • Conduct regular employee training on recognizing phishing campaigns.
  • Encrypt sensitive data and maintain offline backups to mitigate ransom demands.

Suggested Tags

Ransomware
Financial Crime
Data Extortion
Healthcare Sector
Critical Infrastructure

Confidence Assessment

The threat intelligence on GOLD SOUTHFIELD is moderately high, with confident data on their operation of REvil RaaS and their shift to data extortion. However, specific details about individual campaigns, exact TTPs, and the full extent of their capabilities are somewhat fragmented across sources.

ATT&CK Techniques

Initial Access
4 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Secureworks REvil September 2019 — Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.
  2. CrowdStrike Evolution of Pinchy Spider July 2021 — Meyers, Adam. (2021, July 6). The Evolution of PINCHY SPIDER from GandCrab to REvil. Retrieved March 28, 2023.
  3. Secureworks GandCrab and REvil September 2019 — Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.
  4. Secureworks GOLD SOUTHFIELD — Secureworks. (n.d.). GOLD SOUTHFIELD. Retrieved October 6, 2020.

Intel Summary

9

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

6

Tactics

Tags

Ransomware
APT
Critical Infrastructure
Financial Crime
Data Extortion
Healthcare Sector

Details

MITRE ID
G0115
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--c77c5576-ca19-42ed-a36f-4b4486a84133
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.