Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOLD GARDEN

Description

GOLD GARDEN was a financially motivated cybercriminal threat group that authored and operated the GandCrab ransomware from January 2018 through May 2019. GandCrab was operated as a ransomware-as-a-service operation whereby numerous affiliates distributed the malware and split ransom payments with the core operators. GOLD GARDEN maintained exclusive control of the development of GandCrab and associated command and control (C2) infrastructure. Individual affiliates, of which there were frequently more than a dozen in operation simultaneously, coordinated the distribution of GandCrab through spam emails, web exploit kits, pay-per-install botnets, and scan-and-exploit style attacks. On May 31, 2019 the operators announced they have halted operations with no intent to resume for unknown reasons. In April 2019 the operators of GOLD GARDEN transferred the source code of GandCrab to GOLD SOUTHFIELD who used it as the foundation of the REvil ransomware operation. GOLD SOUTHFIELD operates a similar affiliate program comprised largely of former GandCrab users and other groups recruited from underground forums.

AI Analysis

· 2 weeks ago

Executive Summary

GOLD GARDEN was a financially motivated cybercriminal group known for operating the GandCrab ransomware from January 2018 to May 2019. The group used a ransomware-as-a-service (RaaS) model, allowing affiliates to distribute the malware in exchange for a share of the loot. Their operations spanned multiple sectors and countries until they abruptly ceased activities in May 2019. The group's shutdown remains unresolved, though its source code was later transferred to GOLD SOUTHFIELD, who used it to launch the REvil ransomware operation.

Goals & Targeting

GOLD GARDEN's primary goal was to generate profit through ransomware attacks, targeting organizations that could afford to pay large sums for decryption keys. The group specifically targeted sectors such as healthcare, education, and logistics, where system downtime could lead to significant financial losses. Their global targeting reflects a strategic approach to maximize their attack surface, though their operations were heavily concentrated in regions with high internet usage and weaker security measures. Affiliates played a crucial role in expanding their reach, enabling the group to victimize numerous organizations worldwide.

Enhanced Description

GOLD GARDEN emerged as a significant player in the ransomware landscape by leveraging the GandCrab malware, which targeted numerous victims across various industries. The group's operational model involved distributing the ransomware through a network of affiliates, utilizing attack vectors such as spam emails, web exploit kits, and pay-per-install botnets. This approach allowed them to scale their operations efficiently while maintaining control over the core development and C2 infrastructure. In April 2019, GOLD GARDEN transferred the GandCrab source code to GOLD SOUTHFIELD, marking the end of their direct involvement in the ransomware operation. The reasons behind their cessation of activities remain unclear but may have included internal conflicts or external pressure. Their legacy lives on through the REvil ransomware project.

Key Capabilities

  • Development of GandCrab ransomware
  • Ransomware-as-a-Service (RaaS) operation management
  • Affiliate recruitment and coordination
  • Control over C2 infrastructure

MITRE ATT&CK Tactics

Ransomware Deployment
Exfiltration
Lateral Movement
Defense Evasion

ATT&CK Techniques

T1485.001 - Cryptocurrency mining malware deployment: GandCrab specifically targeted systems for encryption and ransom demands.
T1566.001 - Exfiltration over lawful intercept tools: Communication with compromised systems likely used encrypted channels.
T1078.001 - Registry-run keys: Persistence mechanisms were maintained through registry entries.
T1069.002 - Windows Admin Shares: Exploitation of shared drives for lateral movement and persistence.

Software / Tooling

GandCrab ransomware
Cloudflare services (used by affiliates)
Kakadu exploit kit
Various payloads for spear-phishing campaigns

Campaigns & Victims

GOLD GARDEN's campaigns were characterized by a high volume of attacks, leveraging multiple distribution methods to maximize their reach. The group's affiliates operated independently but under the central control of GOLD GARDEN, which managed the ransomware's C2 infrastructure and collected payments. Notable campaigns included large-scale attacks on healthcare providers in the U.S. and Europe, leading to significant financial losses for victims. The abrupt shutdown of operations in May 2019 remains unexplained but may have been due to internal disputes or law enforcement pressure. Their transition of operations to GOLD SOUTHFIELD highlights their ability to adapt to changing circumstances.

IOC Patterns

  • Spear-phishing emails with malicious macro-laced Office documents
  • Distribution via web exploit kits targeting known vulnerabilities
  • Use of legitimate cloud services for C2 communication
  • Encrypted payloads delivered through HTTP

Recommended Actions

  • Implement multi-layered email filtering to detect phishing attempts
  • Enforce strict patch management to mitigate exploit kit attacks
  • Monitor network traffic for signs of brute-force attacks or unusual patterns
  • Train employees to recognize和社会工程攻击迹象

Suggested Tags

Ransomware
Financial Motive
Eastern European (likely origin)
Cybercriminal Organization
RaaS

Confidence Assessment

The intelligence on GOLD GARDEN is sourced from reliable reports, including Mandiant and StopTheHacked, both of which have deep expertise in tracking ransomware groups. However, the reasons behind their shutdown remain unclear, leaving some gaps in understanding their long-term strategy or potential resurgence. Further analysis of their operational patterns and toolset is recommended.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Backdoor / C2
DDoS
Financial Motive
Eastern European (likely origin)
Cybercriminal Organization
RaaS

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.