GOLD FLANDERS is a financially motivated group known for high-volume DDoS attacks demanding bitcoin ransoms.
Analyst brief
GOLD FLANDERS is a financially motivated group conducting extortion-driven DDoS attacks accompanied by threatening emails. It targets specific Autonomous System Numbers (ASNs) or IP address ranges, demanding 5 to 30 bitcoins. Their main TTPs involve high-volume DDoS attacks using fragmented UDP packets via DNS and NTP reflection, reaching 20-200 Gbps and 12-15 million packets per second for 20-70 minutes. Defenders must focus on configuring DDoS mitigation for large-scale UDP reflection attacks, especially those coinciding with extortion emails demanding cryptocurrency payments.
GOLD FLANDERS
unknown
GOLD FLANDERS is a financially motivated group responsible for distributed denial of service (DDOS) attacks linked to extortion emails demanding between 5 and 30 bitcoins. The attacks consist mostly of fragmented UDP packets (DNS and NTP reflection) as well as other traffic that can vary per victim. The arrival of the extortion email is timed to coincide with a DDOS attack consisting of traffic between 20 Gbps and 200 Gbps and 12-15 million packets per second, lasting between 20 and 70 minutes targeted at a particular Autonomous System Number (ASN) or group of IP addresses. In some cases victim organisations have replied to these extortion emails and received personal replies from GOLD FLANDERS operators within 20 minutes.
What DDoS amplification methods does the GOLD FLANDERS group use during their attacks?+
The GOLD FLANDERS group primarily uses DNS and NTP reflection methods to send fragmented UDP packets, launching high-volume DDoS attacks against the target.
What is the ransom demand range of GOLD FLANDERS?+
The GOLD FLANDERS group demands between 5 and 30 bitcoins from targeted organizations.