Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOLD MANSARD

Description

GOLD MANSARD is a financially motivated cybercriminal threat group that operated the Nemty ransomware from August 2019. The threat actor behind Nemty is known on Russian underground forums as 'jsworm'. Nemty was operated as a ransomware as a service (RaaS) affiliate program and featured a 'name and shame' website where exfiltrated victim data was leaked. In April 2020, jsworm appeared to acquire new partners and retired the Nemty ransomware. This was followed by the introduction of Nefilim ransomware, which does not operate as an affiliate model. Nefilim has been used in post-intrusion ransomware attacks against organizations in logistics, telecommunications, energy and other sectors.

AI Analysis

· 1 week ago

Executive Summary

GOLD MANSARD, a financially motivated cybercriminal group, operates Nefilim ransomware following the retirement of Nemty in April 2020. This threat actor targets critical sectors like logistics, telecommunications, and energy with sophisticated ransomware attacks aimed at disrupting operations and extorting high-value ransoms.

Goals & Targeting

GOLD MANSARD primarily focuses on achieving significant financial gains throughansomware attacks. Their strategic targeting of sectors like logistics, telecommunications, and energy suggests a focus on high-impact industries where data breaches and operational disruptions can lead to substantial financial losses. The group's shift from the affiliate model to a more exclusive RaaS indicates an evolution towards more controlled and potentially lucrative operations, aligning with their financially motivated nature.

Enhanced Description

GOLD MANSARD is a financially motivated cybercriminal group known for their association with the Nemty ransomware from August 2019 onwards. The group's operator, 'jsworm,' is active on Russian underground forums. In April 2020, after ceasing operations of Nemty as a ransomware-as-a-service (RaaS) affiliate program, they introduced Nefilim ransomware, which does not utilize an affiliate model. Nefilim has been employed in post-intrusion ransomware attacks against organizations across various sectors including logistics, telecommunications, energy, and others. The group is known for their 'name and shame' tactic, where exfiltrated data is leaked to coerce victims into paying ransoms. Their shift from an affiliate-based model suggests a strategic evolution towards more direct and potentially high-value targets. GOLD MANSARD's activities highlight the growing sophistication of ransomware operators, particularly in targeting critical infrastructure and leveraging extortion tactics to maximize financial gains.

Key Capabilities

  • Ransomware development and deployment
  • Name-and-shame tactics to pressure victims
  • Post-intrusion ransomware attacks
  • Exfiltration of victim data for blackmail purposes

MITRE ATT&CK Tactics

Defense Evasion
Credential Access
Exfiltration
Impact Infrastructure

ATT&CK Techniques

T1568.001 - Data Encryption
T1543.004 - Ransom Note via Alternate Communication Channel
T1070 - Network Exfiltration AcrossChannels
T1214 - Compromise Accounts Using Credential Phishing
T1086.001 - PsExec

Software / Tooling

Nemty Ransomware
Nefilim Ransomware
Spear-phishing Tools
Data Exfiltration Tools
Command-and-Control Communication Tools

Campaigns & Victims

GOLD MANSARD's campaign patterns include targeting critical infrastructure sectors, leveraging post-intrusion ransomware deployment, and utilizing shakedown tactics through data leaks. Their operational tempo involves prolonged presence within networks to ensure maximum disruption and financial gain. Notable campaigns include the Nefilim attacks, which exhibit increased sophistication compared to Nemty.

IOC Patterns

  • Spear-phishing emails deploying Nefilim/Nemty ransomware
  • Encrypted files indicative of ransomware encryption
  • Network communication patterns consistent with C2 infrastructure
  • Exfiltration of sensitive data over time
  • Presence of lateral movement and persistence mechanisms

Recommended Actions

  • Implement advanced endpoint detection to identify spear-phishing attempts
  • Monitor for unusual network traffic indicative of data exfiltration
  • Enhance backup strategies with air-gapped solutions to prevent ransomware impact
  • Conduct regular user training on phishing and ransomware awareness
  • Enforce multifactor authentication (MFA) for critical accounts

Suggested Tags

ransomware
financial-motivation
critical-infrastructure-targeting
logistics
telecommunications
energy

Confidence Assessment

Moderate confidence in identified TTPs and campaign patterns, with gaps in detailed technical indicators beyond known samples and specifics of their attack methodologies.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
ransomware
financial-motivation
critical-infrastructure-targeting
logistics
telecommunications
energy

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.