GOLD CABIN is a financially motivated cybercriminal group known for its email-based malware distribution service delivering banking trojans.
Analyst brief
GOLD CABIN (aka TA551, Shathak) is a financially motivated cybercriminal group operating a malware distribution service since 2018. The group targets a wide range of organizations, particularly financial institutions, to deliver banking trojans. Key TTPs include Spearphishing Attachment via password-protected archives, defense evasion using Regsvr32 and Rundll32, and DGA-based C2 infrastructure to deploy payloads like QakBot, IcedID, and Ursnif. Defenders should enforce strict email security controls for password-protected archives, enhance network monitoring for DGA-generated C2 traffic, and actively track IOCs related to the deployed malware families, especially QakBot and IcedID.
GOLD CABIN
ShakthakTA551ATK236
unknown
GOLD CABIN is a financially motivated cybercriminal threat group operating a malware distribution service on behalf of numerous customers since 2018. GOLD CABIN uses malicious documents, often contained in password-protected archives, delivered through email to download and execute payloads. The second-stage payloads are most frequently Gozi ISFB (Ursnif) or IcedID (Bokbot), sometimes using intermediary malware like Valak. GOLD CABIN infrastructure relies on artificial appearing and frequently changing URLs created with a domain generation algorithm (DGA). The URLs host a PHP object that returns the malware as a DLL file.