GOLD MANSARD is a financially motivated cybercriminal threat group that operated the Nemty ransomware from August 2019. The threat actor behind Nemty is known on Russian underground forums as 'jsworm'. Nemty was operated as a ransomware as a service (RaaS) affiliate program and featured a 'name and shame' website where exfiltrated victim data was leaked. In April 2020, jsworm appeared to acquire new partners and retired the Nemty ransomware. This was followed by the introduction of Nefilim ransomware, which does not operate as an affiliate model. Nefilim has been used in post-intrusion ransomware attacks against organizations in logistics, telecommunications, energy and other sectors.
Executive Summary
GOLD MANSARD, a financially motivated cybercriminal group, operates Nefilim ransomware following the retirement of Nemty in April 2020. This threat actor targets critical sectors like logistics, telecommunications, and energy with sophisticated ransomware attacks aimed at disrupting operations and extorting high-value ransoms.
Goals & Targeting
GOLD MANSARD primarily focuses on achieving significant financial gains throughansomware attacks. Their strategic targeting of sectors like logistics, telecommunications, and energy suggests a focus on high-impact industries where data breaches and operational disruptions can lead to substantial financial losses. The group's shift from the affiliate model to a more exclusive RaaS indicates an evolution towards more controlled and potentially lucrative operations, aligning with their financially motivated nature.
Enhanced Description
GOLD MANSARD is a financially motivated cybercriminal group known for their association with the Nemty ransomware from August 2019 onwards. The group's operator, 'jsworm,' is active on Russian underground forums. In April 2020, after ceasing operations of Nemty as a ransomware-as-a-service (RaaS) affiliate program, they introduced Nefilim ransomware, which does not utilize an affiliate model. Nefilim has been employed in post-intrusion ransomware attacks against organizations across various sectors including logistics, telecommunications, energy, and others. The group is known for their 'name and shame' tactic, where exfiltrated data is leaked to coerce victims into paying ransoms. Their shift from an affiliate-based model suggests a strategic evolution towards more direct and potentially high-value targets. GOLD MANSARD's activities highlight the growing sophistication of ransomware operators, particularly in targeting critical infrastructure and leveraging extortion tactics to maximize financial gains.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOLD MANSARD's campaign patterns include targeting critical infrastructure sectors, leveraging post-intrusion ransomware deployment, and utilizing shakedown tactics through data leaks. Their operational tempo involves prolonged presence within networks to ensure maximum disruption and financial gain. Notable campaigns include the Nefilim attacks, which exhibit increased sophistication compared to Nemty.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in identified TTPs and campaign patterns, with gaps in detailed technical indicators beyond known samples and specifics of their attack methodologies.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics