Operational since at least October 2020, GOLD NORTHFIELD is a financially motivated cybercriminal threat group that leverages GOLD SOUTHFIELD's REvil ransomware in their attacks. To do this, the threat actors replace the configuration of the REvil ransomware binary with their own in an effort to repurpose the ransomware for their operations. GOLD NORTHFIELD has given this modified REvil ransomware variant the name 'LV ransomware'.
Executive Summary
GOLD NORTHFIELD is a financially motivated cybercriminal threat group operational since October 2020, known for repurposing REvil ransomware to create the 'LV ransomware' variant. Their primary focus is financial gain through targeted ransomware campaigns, often employing sophisticated tactics to disrupt operations and demand ransoms.
Goals & Targeting
GOLD NORTHFIELD's primary motivation is financial gain through ransomware attacks. They target sectors with high financial stakes and sensitive data, such as healthcare and finance, to maximize disruption and potential payouts. Their victims are typically organizations where operational continuity is critical, making them more likely to pay ransoms.
Enhanced Description
GOLD NORTHFIELD operates as a cybercriminal group with a clear focus on financial motivations. They have rebranded REvil ransomware into 'LV ransomware' by modifying its configuration, allowing them to leverage existing malware capabilities for their attacks. This group primarily targets sectors where financial gain is prioritized, such as healthcare, finance, and education. Their operations involve strategic tactics including phishing emails, vulnerability exploits, and encrypted command-and-control communication to maintain operational stealth. Understanding their TTPs, which include initial access via phishing,狡猾的传播手段,以及利用现成软件进行分发,对于防御至关重要。
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOLD NORTHFIELD's campaigns exhibit a methodical approach, with phishing emails as their entry vector and encrypted communication for C2. They have demonstrated the ability to adapt their methods to enhance stealth and effectiveness, likely evolving their tactics over time based on victim responses and security measures.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is a high confidence in GOLD NORTHFIELD's operational pattern and their use of modified REvil ransomware. However, details on specific campaigns and exact targeting countries remain unclear.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics