GOLD SOUTHFIELD — Ransomware Profile
GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.Also tracked as
Pinchy Spider, PINCHY SPIDER
Tools & malware
- ConnectWise Remote Access
- REvil Ransomware
Vendor research
- REvil/Sodinokibi Ransomware Counter Threat Unit Research Team
- REvil: The GandCrab Connection Secureworks
- GOLD SOUTHFIELD Secureworks
- REvil/Sodinokibi Ransomware Secureworks
- Secureworks. (n.d.). GOLD SOUTHFIELD Secureworks
- The Evolution of PINCHY SPIDER from GandCrab to REvil Crowdstrike
- REvil: The GandCrab Connection Secureworks