Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOLD NORTHFIELD

Description

Operational since at least October 2020, GOLD NORTHFIELD is a financially motivated cybercriminal threat group that leverages GOLD SOUTHFIELD's REvil ransomware in their attacks. To do this, the threat actors replace the configuration of the REvil ransomware binary with their own in an effort to repurpose the ransomware for their operations. GOLD NORTHFIELD has given this modified REvil ransomware variant the name 'LV ransomware'.

AI Analysis

· 1 week ago

Executive Summary

GOLD NORTHFIELD is a financially motivated cybercriminal threat group operational since October 2020, known for repurposing REvil ransomware to create the 'LV ransomware' variant. Their primary focus is financial gain through targeted ransomware campaigns, often employing sophisticated tactics to disrupt operations and demand ransoms.

Goals & Targeting

GOLD NORTHFIELD's primary motivation is financial gain through ransomware attacks. They target sectors with high financial stakes and sensitive data, such as healthcare and finance, to maximize disruption and potential payouts. Their victims are typically organizations where operational continuity is critical, making them more likely to pay ransoms.

Enhanced Description

GOLD NORTHFIELD operates as a cybercriminal group with a clear focus on financial motivations. They have rebranded REvil ransomware into 'LV ransomware' by modifying its configuration, allowing them to leverage existing malware capabilities for their attacks. This group primarily targets sectors where financial gain is prioritized, such as healthcare, finance, and education. Their operations involve strategic tactics including phishing emails, vulnerability exploits, and encrypted command-and-control communication to maintain operational stealth. Understanding their TTPs, which include initial access via phishing,狡猾的传播手段,以及利用现成软件进行分发,对于防御至关重要。

Key Capabilities

  • Modification of REvil ransomware into 'LV ransomware'
  • Phishing campaigns with malicious attachments
  • Exploitation of system vulnerabilities
  • Use of encrypted C2 communication channels

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Communication

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1078

Software / Tooling

REvil ransomware (modified)
Phishing tools

Campaigns & Victims

GOLD NORTHFIELD's campaigns exhibit a methodical approach, with phishing emails as their entry vector and encrypted communication for C2. They have demonstrated the ability to adapt their methods to enhance stealth and effectiveness, likely evolving their tactics over time based on victim responses and security measures.

IOC Patterns

  • Spear-phishing emails with malicious Office attachments
  • Encrypted network traffic indicative of C2 channels
  • Presence of 'LV ransomware' file signatures

Recommended Actions

  • Implement robust email filtering to detect phishing attempts.
  • Regularly patch systems to mitigate vulnerabilities.
  • Monitor network traffic for signs of encrypted command-and-control communication.
  • Establish data backups to ensure business continuity in the event of a ransomware attack.

Suggested Tags

Financial Motivation
Ransomware
Cybercriminal Group

Confidence Assessment

There is a high confidence in GOLD NORTHFIELD's operational pattern and their use of modified REvil ransomware. However, details on specific campaigns and exact targeting countries remain unclear.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial Motivation
Cybercriminal Group

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.