GOLD DUPONT is a financially motivated group known for post-intrusion ransomware attacks.
Analyst brief
GOLD DUPONT is a financially motivated cybercriminal group, active since November 2018, specializing in post-intrusion ransomware attacks. They primarily use stolen credentials to access remote services like VDI or VPN, and have also leveraged TrickBot and IcedID malware as initial access vectors. The group deploys the 777 (Defray777/RansomExx) ransomware. Defenders should enforce multi-factor authentication on remote access services, monitor for credential leaks, and strengthen network detection for TrickBot and IcedID infections.
GOLD DUPONT
SPRITE SPIDER
unknown
GOLD DUPONT is a financially motivated cybercriminal threat group that specializes in post-intrusion ransomware attacks using 777 (aka Defray777 or RansomExx) malware. Active since November 2018, GOLD DUPONT establishes initial access into victim networks using stolen credentials to remote access services like virtual desktop infrastructure (VDI) or virtual private networks (VPN). From October 2019 to early 2020 the group used GOLD BLACKBURN's TrickBot malware as an initial access vector (IAV) during some intrusions. Since July 2020, the group has also used GOLD SWATHMORE's IcedID (Bokbot) malware as an IAV in some intrusions.
What method does the GOLD DUPONT group typically use for initial network access?+
They primarily use stolen credentials to access remote services like VDI or VPN, and have also leveraged TrickBot and IcedID malware as initial access vectors.
What ransomware tool does the GOLD DUPONT group deploy?+
The group deploys the 777 (Defray777/RansomExx) ransomware.