Also known as: Pinchy Spider
GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.(Citation: Secureworks REvil September 2019)(Citation: Secureworks GandCrab and REvil September 2019)(Citation: Secureworks GOLD SOUTHFIELD)(Citation: CrowdStrike Evolution of Pinchy Spider July 2021)
Executive Summary
GOLD SOUTHFIELD, also known as Pinchy Spider, is a financially motivated threat actor that operates the REvil Ransomware-as-a-Service (RaaS) platform since at least 2018. Initially focused on traditional ransomware, they evolved by leveraging stolen data to extort victims beyond payment demands in early 2020. Their strategic shift to data theft and extortion significantly increases the pressure on targeted organizations.
Goals & Targeting
GOLD SOUTHFIELD primarily seeks financial gain through ransomware campaigns and data extortion, targeting sectors such as healthcare, education, and critical infrastructure. Their focus on these sectors is driven by the potential for higher ransoms, availability of sensitive data, and the victims' desire to avoid public exposure of stolen information. The group's strategic choice of targets reflects a deep understanding of which industries are most vulnerable to both financial pressure and reputational damage.
Enhanced Description
GOLD SOUTHFIELD is a sophisticated threat actor that operates the REvil RaaS platform, enabling affiliates to execute high-value ransomware attacks. By recruiting affiliates through underground forums, the group has expanded its operational scope, focusing on both traditional ransomware deployment and data theft followed by extortion. Their evolution in tactics, particularly their emphasis on stealing sensitive data and threatening public leaks, highlights a shift towards more damaging and high-stakes operations. This approach not only increases financial gains but also raises the stakes for victims who may face significant reputational damage alongside financial losses. The group's ability to adapt their tactics underscores their strategic ingenuity and operational resilience in the cybercrime landscape.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOLD SOUTHFIELD's campaigns typically involve targeted phishing attacks, followed by ransomware deployment and data exfiltration. They have been observed targeting organizations with robust encryption and a focus on sectors with high data sensitivity. Notable past operations include REvil-related incidents where victims were threatened with data leaks if ransoms weren't paid.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The threat intelligence on GOLD SOUTHFIELD is moderately high, with confident data on their operation of REvil RaaS and their shift to data extortion. However, specific details about individual campaigns, exact TTPs, and the full extent of their capabilities are somewhat fragmented across sources.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
9
Techniques
2
Tools
0
Campaigns
0
IOCs
0
Observed Data
6
Tactics