GOLD FLANDERS is a financially motivated group responsible for distributed denial of service (DDOS) attacks linked to extortion emails demanding between 5 and 30 bitcoins. The attacks consist mostly of fragmented UDP packets (DNS and NTP reflection) as well as other traffic that can vary per victim. The arrival of the extortion email is timed to coincide with a DDOS attack consisting of traffic between 20 Gbps and 200 Gbps and 12-15 million packets per second, lasting between 20 and 70 minutes targeted at a particular Autonomous System Number (ASN) or group of IP addresses. In some cases victim organisations have replied to these extortion emails and received personal replies from GOLD FLANDERS operators within 20 minutes.
Executive Summary
GOLD FLANDERS is a financially motivated threat actor known for conducting Distributed Denial of Service (DDOS) attacks paired with extortion emails demanding bitcoins. The group's operations involve high-intensity DDoS campaigns using fragmented UDP packets and other traffic types, often targeting specific ASNs or IP groups. Victims have reported receiving personalized replies from the actors within minutes of contacting them via extortion emails.
Goals & Targeting
GOLD FLANDERS' primary strategic objective appears to be financial gain through extortion and disruption. Their targeting profile suggests a focus on industries where high-profile attacks could yield significant ransom payments, such as large enterprises in the retail, healthcare, or financial sectors. The group's global operational reach implies that any country hosting high-value targets is at risk.
Enhanced Description
GOLD FLANDERS operates as a financially motivated threat group primarily engaging in DDoS attacks and extortion activities. The group's modus operandi involves launching significant DDoS campaigns, with traffic ranging from 20 Gbps to 200 Gbps and packet rates of 12-15 million per second, targeting specific ASNs or IP addresses. These attacks are strategically timed to coincide with the delivery of extortion emails demanding between 5 to 30 bitcoins. The group's ability to respond quickly—replying to victims within 20 minutes—demonstrates a high level of operational efficiency and sophistication. While no specific tools or infrastructure have been conclusively linked to GOLD FLANDERS, their use of DDoS attacks suggests a potential reliance on botnets or other amplification networks. The group's targeting appears to focus on sectors where financial gain is maximized, such as retail, e-commerce, or financial services, though this remains speculative.
Key Capabilities
Campaigns & Victims
GOLD FLANDERS' campaigns are characterized by their high-intensity DDoS attacks and rapid extortion efforts. Victims have reported receiving personalized responses when engaging with the group, indicating a structured operational approach. The group's focus on financial gain aligns with broader trends in cybercrime, but specific campaign patterns beyond the described TTPs remain unclear due to limited公开 reporting.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in the details of GOLD FLANDERS' activities, tools, and exact targeting criteria due to limited公开 reporting. Additional information on their specific TTPs and toolset would improve understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics