Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOLD WATERFALL

Description

GOLD WATERFALL is a group of financially motivated cybercriminals responsible for the creation, distribution, and operation of the Darkside ransomware. Active since August 2020, GOLD WATERFALL uses a variety of tactics, techniques, and procedures (TTPs) to infiltrate and move laterally within targeted organizations to deploy Darkside ransomware to its most valuable resources. Among these TTPs are using malicious documents delivered by email to establish a foothold and using stolen credentials to access victims' remote access services. In November 2020, the 'darksupp' persona was observed advertising an affiliate program on several semi-exclusive underground forums, marking GOLD WATERFALL's entry into the ransomware-as-a-service (RaaS) landscape.

AI Analysis

· 1 week ago

Executive Summary

GOLD WATERFALL is a financially motivated cybercriminal group known for operating the Darkside ransomware. They use tactics such as malicious email documents and stolen credentials to infiltrate organizations, with notable attacks like the Colonial Pipeline incident.

Goals & Targeting

GOLD WATERFALL's primary goal is financial gain through ransomware operations. They target industries with high-value data and critical infrastructure, such as energy sectors, to maximize payouts. Their global targeting indicates a focus on diverse victims across various regions.

Enhanced Description

GOLD WATERFALL operates since August 2020, utilizing Darkside ransomware in attacks targeting various industries globally. The group employs phishing emails with malicious attachments and leverages stolen credentials for initial access, often moving laterally across networks to deploy their ransomware. In November 2020, they joined the Ransomware-as-a-Service (RaaS) landscape by offering an affiliate program through 'darksupp,' expanding their attack capabilities.

Key Capabilities

  • Malicious email campaigns
  • Stolen credential misuse
  • Ransomware deployment
  • RaaS operations

MITRE ATT&CK Tactics

Initial Access
Credential Access

ATT&CK Techniques

T1566
T1078

Software / Tooling

Darkside Ransomware
Mimikatz (for credential dumping)
Custom scripts

Campaigns & Victims

GOLD WATERFALL's affiliate program marked their shift to RaaS. They focus on high-value targets, exemplified by the Colonial Pipeline attack. Their campaigns are characterized by persistence and a preference for remote access services as entry points.

IOC Patterns

  • Spear-phishing emails with malicious Office documents
  • C2 communication via stolen credentials
  • Abuse of remote desktop protocols
  • Staged infrastructure use

Recommended Actions

  • Implement multi-factor authentication for remote access
  • Monitor and analyze logs for unusual activity
  • Conduct regular backup assessments
  • Perform incident response exercises focusing on ransomware scenarios
  • Stay updated on TTPs of known threat groups

Suggested Tags

Ransomware
Financial Motive
Cybercrime

Confidence Assessment

Medium confidence due to availability of secondary intelligence. Gaps include specific targeting sectors and countries beyond financial motivation, as well as no linked MISP entries.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Financial Motive
Cybercrime

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.