GOLD GARDEN was a financially motivated cybercriminal threat group that authored and operated the GandCrab ransomware from January 2018 through May 2019. GandCrab was operated as a ransomware-as-a-service operation whereby numerous affiliates distributed the malware and split ransom payments with the core operators. GOLD GARDEN maintained exclusive control of the development of GandCrab and associated command and control (C2) infrastructure. Individual affiliates, of which there were frequently more than a dozen in operation simultaneously, coordinated the distribution of GandCrab through spam emails, web exploit kits, pay-per-install botnets, and scan-and-exploit style attacks. On May 31, 2019 the operators announced they have halted operations with no intent to resume for unknown reasons. In April 2019 the operators of GOLD GARDEN transferred the source code of GandCrab to GOLD SOUTHFIELD who used it as the foundation of the REvil ransomware operation. GOLD SOUTHFIELD operates a similar affiliate program comprised largely of former GandCrab users and other groups recruited from underground forums.
Executive Summary
GOLD GARDEN was a financially motivated cybercriminal group known for operating the GandCrab ransomware from January 2018 to May 2019. The group used a ransomware-as-a-service (RaaS) model, allowing affiliates to distribute the malware in exchange for a share of the loot. Their operations spanned multiple sectors and countries until they abruptly ceased activities in May 2019. The group's shutdown remains unresolved, though its source code was later transferred to GOLD SOUTHFIELD, who used it to launch the REvil ransomware operation.
Goals & Targeting
GOLD GARDEN's primary goal was to generate profit through ransomware attacks, targeting organizations that could afford to pay large sums for decryption keys. The group specifically targeted sectors such as healthcare, education, and logistics, where system downtime could lead to significant financial losses. Their global targeting reflects a strategic approach to maximize their attack surface, though their operations were heavily concentrated in regions with high internet usage and weaker security measures. Affiliates played a crucial role in expanding their reach, enabling the group to victimize numerous organizations worldwide.
Enhanced Description
GOLD GARDEN emerged as a significant player in the ransomware landscape by leveraging the GandCrab malware, which targeted numerous victims across various industries. The group's operational model involved distributing the ransomware through a network of affiliates, utilizing attack vectors such as spam emails, web exploit kits, and pay-per-install botnets. This approach allowed them to scale their operations efficiently while maintaining control over the core development and C2 infrastructure. In April 2019, GOLD GARDEN transferred the GandCrab source code to GOLD SOUTHFIELD, marking the end of their direct involvement in the ransomware operation. The reasons behind their cessation of activities remain unclear but may have included internal conflicts or external pressure. Their legacy lives on through the REvil ransomware project.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOLD GARDEN's campaigns were characterized by a high volume of attacks, leveraging multiple distribution methods to maximize their reach. The group's affiliates operated independently but under the central control of GOLD GARDEN, which managed the ransomware's C2 infrastructure and collected payments. Notable campaigns included large-scale attacks on healthcare providers in the U.S. and Europe, leading to significant financial losses for victims. The abrupt shutdown of operations in May 2019 remains unexplained but may have been due to internal disputes or law enforcement pressure. Their transition of operations to GOLD SOUTHFIELD highlights their ability to adapt to changing circumstances.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence on GOLD GARDEN is sourced from reliable reports, including Mandiant and StopTheHacked, both of which have deep expertise in tracking ransomware groups. However, the reasons behind their shutdown remain unclear, leaving some gaps in understanding their long-term strategy or potential resurgence. Further analysis of their operational patterns and toolset is recommended.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics