GOLD SYMPHONY is a Russia-based financially motivated group known for offering Buer Loader as a MaaS.
Analyst brief
GOLD SYMPHONY is a financially motivated cybercrime group, likely based in Russia, known for developing and selling the Buer Loader malware. They primarily operate by offering Buer Loader as a malware-as-a-service (MaaS) on underground forums to other threat actors, including GOLD BLACKBURN (TrickBot operators). Their main TTP involves using Buer Loader to gain initial access and subsequently deliver TrickBot, Cobalt Strike, and other ransomware deployment tools. Defenders should focus on detecting malicious document macros, unusual process execution chains, and C2 traffic related to Cobalt Strike and TrickBot.
GOLD SYMPHONY
unknown
GOLD SYMPHONY is a financially motivated cybercrime group, likely based in Russia, that is responsible for the development and sale on underground forums of the Buer Loader malware. First discovered around August 2019, Buer Loader is offered as a malware-as-a-service (MasS) and has been advertised by a threat actor using the handle 'memeos'. Customers include GOLD BLACKBURN, the operators of the TrickBot malware. In addition to TrickBot, Buer Loader has been reported to download Cobalt Strike and other tools for use in post-intrusion ransomware attacks.