Also known as: SPRITE SPIDER
GOLD DUPONT is a financially motivated cybercriminal threat group that specializes in post-intrusion ransomware attacks using 777 (aka Defray777 or RansomExx) malware. Active since November 2018, GOLD DUPONT establishes initial access into victim networks using stolen credentials to remote access services like virtual desktop infrastructure (VDI) or virtual private networks (VPN). From October 2019 to early 2020 the group used GOLD BLACKBURN's TrickBot malware as an initial access vector (IAV) during some intrusions. Since July 2020, the group has also used GOLD SWATHMORE's IcedID (Bokbot) malware as an IAV in some intrusions.
Executive Summary
GOLD DUPONT is a financially motivated cybercriminal group leveraging stolen credentials and banking malware to deploy the 777 ransomware, targeting organizations with vulnerable remote access infrastructures. Active since 2018, the group has evolved its initial access methods, incorporating TrickBot and IcedID malware in different phases of its operations. Their focus on post-intrusion ransomware attacks underscores a persistent campaign to exploit weaknesses in credential management and network segmentation.
Goals & Targeting
GOLD DUPONT's primary objective is financial gain through ransomware, targeting organizations with inadequately secured remote access systems or compromised credentials. The group's preference for exploiting VDI and VPN infrastructure suggests a focus on businesses reliant on remote work environments, including sectors with high-value data or critical operational systems. By leveraging TrickBot and IcedID, the actor capitalizes on the widespread adoption of banking trojans for initial access, enabling it to infiltrate a wide range of industries without requiring direct targeting of specific sectors. This approach broadens its potential victim base while minimizing the need for highly specialized attack vectors.
Enhanced Description
GOLD DUPONT is a financially driven threat actor specializing in post-intrusion ransomware operations using the 777 malware family (also known as Defray777 or RansomExx). Since November 2018, the group has maintained a presence in the cybercriminal landscape, exploiting stolen credentials to gain access to remote access services such as virtual desktop infrastructure (VDI) or virtual private networks (VPN). Between October 2019 and early 2020, GOLD DUPONT utilized GOLD BLACKBURN's TrickBot malware as an initial access vector (IAV), demonstrating adaptability in leveraging existing threat actor infrastructures. Since July 2020, the group has expanded its toolkit to include GOLD SWATHMORE's IcedID (Bokbot) malware, reflecting a strategic shift to exploit a wider range of vulnerabilities. This evolution highlights the group's emphasis on persistence and lateral movement within victim networks prior to deploying ransomware, with the ultimate goal of maximizing financial gain through data encryption and extortion.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOLD DUPONT's campaigns have demonstrated a structured operational tempo, with the group consistently refining its initial access methods over time. Their use of both TrickBot and IcedID highlights a capacity to adapt to the evolving threat landscape, leveraging existing infrastructure from allied threat groups. The actor's campaigns typically involve a multi-stage process: initial access through stolen credentials or malware, lateral movement within the network, data exfiltration, and subsequent deployment of ransomware. No specific sectors or countries have been definitively linked to their activities, though the reliance on remote access services suggests a broad targeting scope.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the described tactics, techniques, and tools is high, based on the group's consistent use of 777 ransomware and exploitation of TrickBot/IcedID. However, targeted sectors, countries, and specific MITRE technique correlations remain less certain due to limited disclosed data. Further analysis of IOCs and campaign attribution could improve contextual precision.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics