GOLD PRELUDE is a financially motivated cybercriminal group known for operating the SocGholish malware distribution network via Parrot TDS.
Analyst brief
GOLD PRELUDE, also tracked as TA569, is a financially motivated cybercriminal group operating the SocGholish malware distribution network. They target public-facing websites, often running vulnerable CMS platforms, to inject redirects into a malicious traffic distribution system known as Parrot TDS. Their primary TTPs involve compromising legitimate websites, serving customized fake browser update pages, and delivering JavaScript-based SocGholish payloads, frequently within compressed archives. Defenders should focus on user awareness regarding fake browser update prompts, routine patching of external-facing websites, and monitoring for execution of suspicious compressed files.
GOLD PRELUDE
TA569UNC1543
unknown
GOLD PRELUDE is a financially motivated cybercriminal threat group that operates the SocGholish (aka FAKEUPDATES) malware distribution network. GOLD PRELUDE operates a large global network of compromised websites, frequently running vulnerable content management systems (CMS), that redirect into a malicious traffic distribution system (TDS). The TDS, which researchers at Avast have named Parrot TDS, uses opaque criteria to select victims to serve a fake browser update page. These pages, which are customized to the specific visiting browser software, download the JavaScript-based SocGholish payload frequently embedded within a compressed archive.
What specific traffic distribution system does the GOLD PRELUDE group use to redirect users from compromised websites?+
GOLD PRELUDE uses a traffic distribution system named Parrot TDS, as named by Avast researchers, to redirect visitors from compromised websites to fake browser update pages.
What is the name of the primary malware delivered by GOLD PRELUDE to victims?+
The primary malware distributed by the group is the JavaScript-based malware called SocGholish.