Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOLD DUPONT

Also known as: SPRITE SPIDER

Description

GOLD DUPONT is a financially motivated cybercriminal threat group that specializes in post-intrusion ransomware attacks using 777 (aka Defray777 or RansomExx) malware. Active since November 2018, GOLD DUPONT establishes initial access into victim networks using stolen credentials to remote access services like virtual desktop infrastructure (VDI) or virtual private networks (VPN). From October 2019 to early 2020 the group used GOLD BLACKBURN's TrickBot malware as an initial access vector (IAV) during some intrusions. Since July 2020, the group has also used GOLD SWATHMORE's IcedID (Bokbot) malware as an IAV in some intrusions.

AI Analysis

· 1 week ago

Executive Summary

GOLD DUPONT is a financially motivated cybercriminal group leveraging stolen credentials and banking malware to deploy the 777 ransomware, targeting organizations with vulnerable remote access infrastructures. Active since 2018, the group has evolved its initial access methods, incorporating TrickBot and IcedID malware in different phases of its operations. Their focus on post-intrusion ransomware attacks underscores a persistent campaign to exploit weaknesses in credential management and network segmentation.

Goals & Targeting

GOLD DUPONT's primary objective is financial gain through ransomware, targeting organizations with inadequately secured remote access systems or compromised credentials. The group's preference for exploiting VDI and VPN infrastructure suggests a focus on businesses reliant on remote work environments, including sectors with high-value data or critical operational systems. By leveraging TrickBot and IcedID, the actor capitalizes on the widespread adoption of banking trojans for initial access, enabling it to infiltrate a wide range of industries without requiring direct targeting of specific sectors. This approach broadens its potential victim base while minimizing the need for highly specialized attack vectors.

Enhanced Description

GOLD DUPONT is a financially driven threat actor specializing in post-intrusion ransomware operations using the 777 malware family (also known as Defray777 or RansomExx). Since November 2018, the group has maintained a presence in the cybercriminal landscape, exploiting stolen credentials to gain access to remote access services such as virtual desktop infrastructure (VDI) or virtual private networks (VPN). Between October 2019 and early 2020, GOLD DUPONT utilized GOLD BLACKBURN's TrickBot malware as an initial access vector (IAV), demonstrating adaptability in leveraging existing threat actor infrastructures. Since July 2020, the group has expanded its toolkit to include GOLD SWATHMORE's IcedID (Bokbot) malware, reflecting a strategic shift to exploit a wider range of vulnerabilities. This evolution highlights the group's emphasis on persistence and lateral movement within victim networks prior to deploying ransomware, with the ultimate goal of maximizing financial gain through data encryption and extortion.

Key Capabilities

  • Exploitation of stolen credentials for remote access (VDI/VPN)
  • Deployment of 777 ransomware for data encryption and extortion
  • Integration of TrickBot and IcedID malware for initial access and credential theft
  • Post-intrusion lateral movement and network exploitation
  • Data exfiltration prior to encryption to increase ransomware impact

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1078.004 - Valid Accounts (stolen credentials for access)
T1486 - Data Encrypted for Impact (777 ransomware)
T1040 - Exfiltration over C2 Channels
T1056 - Credential Dumping (via TrickBot/IcedID)
T1133 - External Remote Services (VDI/VPN exploitation)

Software / Tooling

777 (Defray777/RansomExx)
TrickBot
IcedID (Bokbot)

Campaigns & Victims

GOLD DUPONT's campaigns have demonstrated a structured operational tempo, with the group consistently refining its initial access methods over time. Their use of both TrickBot and IcedID highlights a capacity to adapt to the evolving threat landscape, leveraging existing infrastructure from allied threat groups. The actor's campaigns typically involve a multi-stage process: initial access through stolen credentials or malware, lateral movement within the network, data exfiltration, and subsequent deployment of ransomware. No specific sectors or countries have been definitively linked to their activities, though the reliance on remote access services suggests a broad targeting scope.

IOC Patterns

  • Initial access via stolen credentials to VDI/VPN services
  • Deployment of TrickBot or IcedID as initial access vectors
  • Presence of 777 ransomware files and encryption artifacts
  • Exfiltration indicators related to sensitive data prior to encryption
  • C2 traffic patterns consistent with standard protocols for stealth

Recommended Actions

  • Implement multi-factor authentication (MFA) for all remote access systems (VDI/VPN).
  • Deploy endpoint detection and response (EDR) solutions to detect TrickBot and IcedID presence.
  • Regularly patch and update remote access infrastructure to mitigate exploitation risks.
  • Conduct network segmentation to limit lateral movement post-compromise.
  • Maintain offline backups of critical data to mitigate ransomware impact.
  • Train users to identify phishing attempts that may lead to credential theft.
  • Monitor for anomalous C2 traffic patterns indicative of ransomware deployment.

Suggested Tags

ransomware
cybercriminal
financial-motivation
post-intrusion
TrickBot
IcedID

Confidence Assessment

Confidence in the described tactics, techniques, and tools is high, based on the group's consistent use of 777 ransomware and exploitation of TrickBot/IcedID. However, targeted sectors, countries, and specific MITRE technique correlations remain less certain due to limited disclosed data. Further analysis of IOCs and campaign attribution could improve contextual precision.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
ransomware
cybercriminal
financial-motivation
post-intrusion
TrickBot
IcedID

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.