Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOLD SKYLINE

Description

GOLD SKYLINE is a financially motivated cybercriminal threat group operating from Nigeria engaged in high-value wire fraud facilitated by business email compromise (BEC) and spoofing (BES). Also known as Wire-Wire Group 1 (WWG1), GOLD SKYLINE has been active since at least 2016 and relies heavily on compromised email accounts, social engineering, and increasingly malware to divert inter-organization funds transfers.

AI Analysis

· 1 week ago

Executive Summary

GOLD SKYLINE is a financially motivated cybercriminal group based in Nigeria, known for high-value wire fraud using business email compromise (BEC) and spoofing (BES). Active since at least 2016, the group has evolved its tactics to include malware alongside traditional social engineering techniques. Their primary targets are financial institutions, supply chains, and international businesses.

Goals & Targeting

GOLD SKYLINE’s strategic objective is to maximize financial gain through the unauthorized diversion of funds. Their targeting profile focuses on industries with high transaction volumes and weak internal controls, such as financial services, energy, and logistics. The group appears to prioritize targets based on the ease of exploitation rather than specific geographic or sectoral preferences beyond their operational capabilities.

Enhanced Description

GOLD SKYLINE, also referred to as Wire-Wire Group 1 (WWG1), operates with a clear focus on financial gain through cyber-enabled fraud. The group primarily exploits business email compromise (BEC) and account spoofing techniques to manipulate wire transfers between organizations. Their operations are marked by a strong reliance on social engineering, often leveraging compromised email accounts to impersonate trusted individuals or entities. Over time, GOLD SKYLINE has incorporated malware into its toolset, indicating an increased sophistication in their attack methods. The group’s geographic footprint appears to target high-value financial transactions globally, with a particular focus on sectors like finance and energy where large sums of money are regularly transferred. While based in Nigeria, their campaigns have been observed targeting victims across multiple regions, including North America and Europe.

Key Capabilities

  • Social engineering via business email compromise (BEC)
  • Account spoofing and impersonation
  • Use of malware for compromising systems
  • Exploitation of supply chain vulnerabilities
  • Targeting high-value wire transfers

MITRE ATT&CK Tactics

Infiltration
Initial Access

ATT&CK Techniques

T1059.003
T1486.001
T1078
T1566.001

Software / Tooling

Spear-phishing
Malware (likely custom or repurposed)
Fast-Flux C2 infrastructure

Campaigns & Victims

GOLD SKYLINE’s campaigns typically involve long-term operational cycles, with a focus on maintaining persistence and avoiding detection. Their use of BEC and spoofing techniques suggests an emphasis on low-technical infrastructure requirements, making them accessible to a broader range of targets. Notable past operations include numerous cases of successful wire fraud against financial institutions and multinational corporations. The group’s campaigns often exhibit a slow-burn approach, where they gather sufficient intelligence before executing the fraudulent transfer.

IOC Patterns

  • Spear-phishing with email-based social engineering
  • C2 communication via Fast-Flux domains
  • Compromised email accounts used for wire transfers
  • Use of malware to facilitate account access

Recommended Actions

  • Enhance employee training on BEC and phishing indicators
  • Implement multi-factor authentication (MFA) for critical financial systems
  • Monitor for unusual wire transfer activity with automated alerting
  • Conduct regular internal security audits focused on supply chain vulnerabilities
  • Adopt threat intelligence feeds to identify potential GOLD SKYLINE tactics

Suggested Tags

financial-motivation
business-email-compromise
malware
east african cybercrime

Confidence Assessment

The data on GOLD SKYLINE is moderately reliable, with a clear pattern of activity since 2016. However, there are gaps in understanding their exact toolset and the full scope of their geographic targeting beyond high-value financial transactions. Limited visibility into recent campaign tactics post-2019 suggests potential underreporting.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Phishing
financial-motivation
business-email-compromise
malware
east african cybercrime

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.