GOLD SOUTHFIELD (Pinchy Spider) is a financially motivated cybercriminal group known for authoring and operating REvil ransomware.
Analyst brief
GOLD SOUTHFIELD (also known as Pinchy Spider) is a financially motivated cybercriminal group that authors and operates the REvil (Sodinokibi) ransomware. The group targets a broad range of organizations to encrypt data and demand ransom payments, leveraging a Ransomware-as-a-Service model. Their key TTPs include Exploit Public-Facing Application, PowerShell execution, Remote Access Tools like ConnectWise, and Command Obfuscation for stealth. Defenders should prioritize patching public-facing applications, monitoring remote access tool usage, and detecting obfuscated PowerShell commands.
GOLD SOUTHFIELD
Pinchy Spider
unknown
GOLD SOUTHFIELD is a financially motivated cybercriminal threat group that authors and operates the REvil (aka Sodinokibi) ransomware on behalf of various affiliated threat groups. Operational since April 2019, the group obtained the GandCrab source code from GOLD GARDEN, the operators of GandCrab that voluntarily withdrew their ransomware from underground markets in May 2019. GOLD SOUTHFIELD is responsible for authoring REvil and operating the backend infrastructure used by affiliates (also called partners) to create malware builds and to collect ransom payments from victims. CTU researchers assess with high confidence that GOLD SOUTHFIELD is a former GandCrab affiliate and continues to work with other former GandCrab affiliates.