Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOLD GALLEON

Description

GOLD GALLEON is a financially motivated cybercriminal threat group comprised of at least 20 criminal associates that collectively carry out business email compromise (BEC) and spoofing (BES) campaigns. The group appears to specifically target maritime organizations and their customers. CTU researchers have observed GOLD GALLEON targeting firms in South Korea, Japan, Singapore, Philippines, Norway, U.S., Egypt, Saudi Arabia, and Colombia. The threat actors leverage tools, tactics, and procedures that are similar to those used by other BEC/BES groups CTU researchers have previously investigated, such as GOLD SKYLINE. The groups have used the same caliber of publicly available malware (inexpensive and commodity remote access trojans), crypters, and email lures.

AI Analysis

· 1 week ago

Executive Summary

GOLD GALLEON is a financially motivated cybercriminal group targeting maritime organizations through business email compromise (BEC) and spoofing campaigns. They have demonstrated significant activity across multiple countries, including South Korea, Japan, Singapore, Norway, and the U.S., among others. The group leverages commodity malware and tools similar to other BEC groups, such as GOLD SKYLINE, indicating a focus on cost-effective yet effective operational tradecraft.

Goals & Targeting

GOLD GALLEON's strategic objectives appear to center on financial gain through fraudulent activities. Their targeting of maritime organizations suggests a focus on industries with significant financial transactions and global supply chains. This approach allows them to maximize their return on investment by exploiting the trust relationships within these sectors. The group's international reach indicates a potential intent to diversify victim bases, reducing detection risk while maintaining profitability.

Enhanced Description

GOLD GALLEON operates as a cybercriminal collective comprised of numerous associates targeting maritime sectors globally. Their primary modus operandi involves BEC and BES (Business Email Spoofing) campaigns, which are designed to deceive victims into transferring sensitive information or funds. CTU researchers have observed the group's activity across various regions, including South Korea, Japan, Singapore, Philippines, Norway, U.S., Egypt, Saudi Arabia, and Colombia, suggesting a well-coordinated international reach. The threat actors' use of publicly available tools and malware, such as remote access trojans and crypters, indicates a focus on cost-effective solutions rather than developing sophisticated custom tools. Despite this, their operational success demonstrates an understanding of target sectors' vulnerabilities, particularly in the maritime industry, where high-value transactions make BEC attacks lucrative.

Key Capabilities

  • Business Email Compromise (BEC)
  • Email Spoofing
  • Use of commodity malware and remote access trojans
  • Spoofing attacks targeting maritime organizations
  • Leverage publicly available tools for campaigns

MITRE ATT&CK Tactics

Social Engineering
Credential Access
Persistence
Exfiltration
Collection

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1078
T1076

Software / Tooling

Remote access trojans (RATs)
Publicly available crypters
Spear-phishing tools
Email spoofing infrastructure

Campaigns & Victims

GOLD GALLEON's campaigns are characterized by their use of BEC and BES tactics, often involving well-crafted email lures and domain spoofing. Their operational tempo appears steady, with sustained activity across multiple geographies. Notable past operations include numerous successful fund transfers from maritime organizations to fraudulent accounts, leveraging the trust established within these sectors. The group's ability to adapt their targeting while maintaining a focus on cost-effective tools underscores their effectiveness as a financially motivated threat actor.

IOC Patterns

  • Spear-phishing emails with urgent payment requests
  • Email spoofing using domains mimicking legitimate companies
  • Use of compromised accounts for fraudulent wire transfers
  • Leverage cheap and readily available malware-as-a-service (MaaS) offerings

Recommended Actions

  • Implement stricter email authentication protocols (e.g., DKIM, SPF, DMARC)
  • Educate employees on identifying BEC and BES attempts
  • Enhance fraud detection mechanisms for wire transfers
  • Conduct regular security audits of maritime supply chain partners
  • Monitor for异常交易 patterns in financial systems

Suggested Tags

APT
Fraud
Maritime sector
Business Email Compromise
Financial Fraud

Confidence Assessment

Confidence in the data is moderate, as the group's activity is well-documented but lacks specific details on their exact TTPs and malware variants. The association with other BEC groups like GOLD SKYLINE provides contextual insights but leaves gaps in understanding their unique capabilities. Additional information on their attack campaigns, malware toolset, and victimology would enhance the analysis.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Phishing
Backdoor / C2
APT
Fraud
Maritime sector
Business Email Compromise
Financial Fraud

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.