GOLD RIVERVIEW was a financially motivated cybercriminal group that facilitated the distribution of malware- and scam-laden spam email on behalf of its customers. This threat group authored and sold the Necurs rootkit beginning in early 2014, including to GOLD EVERGREEN who integrated it into Gameover Zeus. GOLD RIVERVIEW also operated a global botnet that was colloquially known as Necurs (CraP2P) and was a major source of spam email from 2016 through 2018. Necurs distributed malware such as GOLD DRAKE's Dridex (Bugat v5), GOLD BLACKBURN's TrickBot, and other families like Locky and FlawedAmmy. Necurs also distributed a large volume of email pushing securities 'pump and dump' scams, rogue pharmacies, and fraudulent dating sites. On March 4, 2019 all three active segments of the Necurs botnet ceased operation and have not since resumed. On March 10, 2020 Microsoft took civil action against GOLD RIVERVIEW and made technical steps that would complicate the threat actors' ability to reconstitute the botnet.
Executive Summary
GOLD RIVERVIEW was a financially motivated cybercriminal group known for operating a global botnet (Necurs) that distributed malware and spam emails. They facilitated the distribution of malicious software, including TrickBot and Dridex, and were involved in large-scale scam campaigns. The group's operations were disrupted in 2019-2020, with Microsoft taking legal action to dismantle their infrastructure.
Goals & Targeting
GOLD RIVERVIEW's primary goal was financial gain through cybercrime activities. They targeted individuals and organizations globally, leveraging spam email campaigns to distribute malware and promote fraudulent schemes. Their targeting was broad, focusing on sectors where they could maximize financial returns, such as commerce, healthcare, and finance, through large-scale operations.
Enhanced Description
GOLD RIVERVIEW operated as a cybercriminal group that specialized in creating and distributing malicious software through spam email campaigns. They were known for their Necurs botnet, which was active from 2016 to 2018 and facilitated the spread of malware such as TrickBot, Dridex, Locky, and FlawedAmmy. The group also distributed fraudulent content like pump-and-dump scams, rogue pharmacies, and dating site fraud. GOLD RIVERVIEW acted as a service provider for other cybercriminal groups, including GOLD EVERGREEN, which integrated Necurs into the Gameover Zeus botnet. Microsoft took legal action against them in March 2020, disrupting their ability to operate further.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOLD RIVERVIEW's campaigns involved large-scale distribution of malware and fraud through their Necurs botnet. Their operations typically targeted victims via spam email, delivering malicious payloads such as TrickBot and Dridex. Notable past operations include the widespread dissemination of 'pump-and-dump' scams and rogue pharmacy offers. The group's operational hiatus in 2019-2020 and subsequent legal action by Microsoft have limited their recent activity.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data about GOLD RIVERVIEW is moderate. While their operations are well-documented for their active period (2014-2020), there may be gaps in understanding their current activities or potential resurgence due to limited recent reporting.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics