GOLD NORTHFIELD is a financially motivated cybercriminal group known for repurposing REvil ransomware as "LV ransomware".
Analyst brief
GOLD NORTHFIELD is a financially motivated cybercriminal group active since at least October 2020. They leverage GOLD SOUTHFIELD's REvil ransomware by replacing its configuration with their own, creating a variant they call 'LV ransomware'. No specific target information was provided, but their primary TTP involves repurposing existing ransomware for their operations. Defenders should focus on detecting REvil indicators, particularly configuration changes, and monitor for anomalous file encryption activities across the network.
GOLD NORTHFIELD
unknown
Operational since at least October 2020, GOLD NORTHFIELD is a financially motivated cybercriminal threat group that leverages GOLD SOUTHFIELD's REvil ransomware in their attacks. To do this, the threat actors replace the configuration of the REvil ransomware binary with their own in an effort to repurpose the ransomware for their operations. GOLD NORTHFIELD has given this modified REvil ransomware variant the name 'LV ransomware'.
Which ransomware family does GOLD NORTHFIELD modify and repurpose for their operations?+
GOLD NORTHFIELD modifies the configuration of GOLD SOUTHFIELD's REvil ransomware to create their own variant called 'LV ransomware' for use in their operations.
What should security teams focus on to detect GOLD NORTHFIELD's activity?+
Defenders should focus on detecting known REvil indicators, particularly configuration file changes, and monitor for anomalous file encryption activities across the network.