GC01
From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered by a known individual (hereinafter “the Provider Operator”).
GC01 (Golden Chickens) is a threat actor known for widespread phishing campaigns via a dedicated MaaS platform.
The GC01 (Golden Chickens) group is a threat actor that operated from late 2017 to late 2018, leveraging a dedicated MaaS (Malware-as-a-Service) provider run by an individual known as 'the Provider Operator'. They targeted a broad range of victims through 14 attributed campaigns, primarily aiming for data theft or initial access. Their main TTPs involved malware distributed via the MaaS platform, likely delivered through phishing emails or weaponized documents. Defenders should focus on strengthening email security posture, enhancing user awareness against phishing, and hunting for historical IoCs associated with the Golden Chickens MaaS infrastructure.
From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered by a known individual (hereinafter “the Provider Operator”).
The GC01 group used a dedicated Malware-as-a-Service (MaaS) platform run by an individual known as the 'Provider Operator'.
The 14 attributed campaigns by the Golden Chickens group primarily aimed for data theft.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.