GOLD WATERFALL is a group of financially motivated cybercriminals responsible for the creation, distribution, and operation of the Darkside ransomware. Active since August 2020, GOLD WATERFALL uses a variety of tactics, techniques, and procedures (TTPs) to infiltrate and move laterally within targeted organizations to deploy Darkside ransomware to its most valuable resources. Among these TTPs are using malicious documents delivered by email to establish a foothold and using stolen credentials to access victims' remote access services. In November 2020, the 'darksupp' persona was observed advertising an affiliate program on several semi-exclusive underground forums, marking GOLD WATERFALL's entry into the ransomware-as-a-service (RaaS) landscape.
Executive Summary
GOLD WATERFALL is a financially motivated cybercriminal group known for operating the Darkside ransomware. They use tactics such as malicious email documents and stolen credentials to infiltrate organizations, with notable attacks like the Colonial Pipeline incident.
Goals & Targeting
GOLD WATERFALL's primary goal is financial gain through ransomware operations. They target industries with high-value data and critical infrastructure, such as energy sectors, to maximize payouts. Their global targeting indicates a focus on diverse victims across various regions.
Enhanced Description
GOLD WATERFALL operates since August 2020, utilizing Darkside ransomware in attacks targeting various industries globally. The group employs phishing emails with malicious attachments and leverages stolen credentials for initial access, often moving laterally across networks to deploy their ransomware. In November 2020, they joined the Ransomware-as-a-Service (RaaS) landscape by offering an affiliate program through 'darksupp,' expanding their attack capabilities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOLD WATERFALL's affiliate program marked their shift to RaaS. They focus on high-value targets, exemplified by the Colonial Pipeline attack. Their campaigns are characterized by persistence and a preference for remote access services as entry points.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Medium confidence due to availability of secondary intelligence. Gaps include specific targeting sectors and countries beyond financial motivation, as well as no linked MISP entries.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics