GOLD SKYLINE is a financially motivated cybercriminal threat group operating from Nigeria engaged in high-value wire fraud facilitated by business email compromise (BEC) and spoofing (BES). Also known as Wire-Wire Group 1 (WWG1), GOLD SKYLINE has been active since at least 2016 and relies heavily on compromised email accounts, social engineering, and increasingly malware to divert inter-organization funds transfers.
Executive Summary
GOLD SKYLINE is a financially motivated cybercriminal group based in Nigeria, known for high-value wire fraud using business email compromise (BEC) and spoofing (BES). Active since at least 2016, the group has evolved its tactics to include malware alongside traditional social engineering techniques. Their primary targets are financial institutions, supply chains, and international businesses.
Goals & Targeting
GOLD SKYLINE’s strategic objective is to maximize financial gain through the unauthorized diversion of funds. Their targeting profile focuses on industries with high transaction volumes and weak internal controls, such as financial services, energy, and logistics. The group appears to prioritize targets based on the ease of exploitation rather than specific geographic or sectoral preferences beyond their operational capabilities.
Enhanced Description
GOLD SKYLINE, also referred to as Wire-Wire Group 1 (WWG1), operates with a clear focus on financial gain through cyber-enabled fraud. The group primarily exploits business email compromise (BEC) and account spoofing techniques to manipulate wire transfers between organizations. Their operations are marked by a strong reliance on social engineering, often leveraging compromised email accounts to impersonate trusted individuals or entities. Over time, GOLD SKYLINE has incorporated malware into its toolset, indicating an increased sophistication in their attack methods. The group’s geographic footprint appears to target high-value financial transactions globally, with a particular focus on sectors like finance and energy where large sums of money are regularly transferred. While based in Nigeria, their campaigns have been observed targeting victims across multiple regions, including North America and Europe.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOLD SKYLINE’s campaigns typically involve long-term operational cycles, with a focus on maintaining persistence and avoiding detection. Their use of BEC and spoofing techniques suggests an emphasis on low-technical infrastructure requirements, making them accessible to a broader range of targets. Notable past operations include numerous cases of successful wire fraud against financial institutions and multinational corporations. The group’s campaigns often exhibit a slow-burn approach, where they gather sufficient intelligence before executing the fraudulent transfer.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data on GOLD SKYLINE is moderately reliable, with a clear pattern of activity since 2016. However, there are gaps in understanding their exact toolset and the full scope of their geographic targeting beyond high-value financial transactions. Limited visibility into recent campaign tactics post-2019 suggests potential underreporting.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics