GOLD BURLAP is a financially motivated cybercriminal group known for deploying Pysa ransomware against the healthcare sector.
Analyst brief
GOLD BURLAP (CYBORG SPIDER) is a financially motivated cybercriminal group responsible for developing the Pysa (Mespinoza) ransomware. They primarily target the healthcare sector. Their main TTPs involve using cross-platform Pysa ransomware versions written in C++ and Python and leveraging 'name and shame' tactics to pressure victims. Defenders should focus on this ransomware targeting healthcare systems, noting that the group likely operates directly rather than as a Ransomware as a Service (RaaS) model.
GOLD BURLAP
CYBORG SPIDER
unknown
GOLD BURLAP is a group of financially motivated criminals responsible for the development of the Pysa ransomware, also referred to as Mespinoza. Pysa is a cross-platform ransomware with known versions written in C++ and Python. As of December 2020, approximately 50 organizations had reportedly been targeted in Pysa ransomware attacks. The operators leverage 'name and shame' tactics to apply additional pressure to victims. As of January 2021, CTU researchers had found no Pysa advertisements on underground forums, which likely indicates that it is not operated as ransomware as a service (RaaS).