GOLD GALLEON is a financially motivated cybercriminal threat group comprised of at least 20 criminal associates that collectively carry out business email compromise (BEC) and spoofing (BES) campaigns. The group appears to specifically target maritime organizations and their customers. CTU researchers have observed GOLD GALLEON targeting firms in South Korea, Japan, Singapore, Philippines, Norway, U.S., Egypt, Saudi Arabia, and Colombia. The threat actors leverage tools, tactics, and procedures that are similar to those used by other BEC/BES groups CTU researchers have previously investigated, such as GOLD SKYLINE. The groups have used the same caliber of publicly available malware (inexpensive and commodity remote access trojans), crypters, and email lures.
Executive Summary
GOLD GALLEON is a financially motivated cybercriminal group targeting maritime organizations through business email compromise (BEC) and spoofing campaigns. They have demonstrated significant activity across multiple countries, including South Korea, Japan, Singapore, Norway, and the U.S., among others. The group leverages commodity malware and tools similar to other BEC groups, such as GOLD SKYLINE, indicating a focus on cost-effective yet effective operational tradecraft.
Goals & Targeting
GOLD GALLEON's strategic objectives appear to center on financial gain through fraudulent activities. Their targeting of maritime organizations suggests a focus on industries with significant financial transactions and global supply chains. This approach allows them to maximize their return on investment by exploiting the trust relationships within these sectors. The group's international reach indicates a potential intent to diversify victim bases, reducing detection risk while maintaining profitability.
Enhanced Description
GOLD GALLEON operates as a cybercriminal collective comprised of numerous associates targeting maritime sectors globally. Their primary modus operandi involves BEC and BES (Business Email Spoofing) campaigns, which are designed to deceive victims into transferring sensitive information or funds. CTU researchers have observed the group's activity across various regions, including South Korea, Japan, Singapore, Philippines, Norway, U.S., Egypt, Saudi Arabia, and Colombia, suggesting a well-coordinated international reach. The threat actors' use of publicly available tools and malware, such as remote access trojans and crypters, indicates a focus on cost-effective solutions rather than developing sophisticated custom tools. Despite this, their operational success demonstrates an understanding of target sectors' vulnerabilities, particularly in the maritime industry, where high-value transactions make BEC attacks lucrative.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOLD GALLEON's campaigns are characterized by their use of BEC and BES tactics, often involving well-crafted email lures and domain spoofing. Their operational tempo appears steady, with sustained activity across multiple geographies. Notable past operations include numerous successful fund transfers from maritime organizations to fraudulent accounts, leveraging the trust established within these sectors. The group's ability to adapt their targeting while maintaining a focus on cost-effective tools underscores their effectiveness as a financially motivated threat actor.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data is moderate, as the group's activity is well-documented but lacks specific details on their exact TTPs and malware variants. The association with other BEC groups like GOLD SKYLINE provides contextual insights but leaves gaps in understanding their unique capabilities. Additional information on their attack campaigns, malware toolset, and victimology would enhance the analysis.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics