GOLD SOUTHFIELD — Ransomware Profile
GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Pinchy Spider, PINCHY SPIDER, REvil, Sodinokibi, GandCrab
IntelFusions coverage (2)
- U.S. Indicts Dmitry Khoroshev as LockBit's Developer and Administrator: $500M Extorted, 2,500 Victims in 120 Countries 2026-02-16 · Ransomware
- REvil Resurfaces: New Samples Confirm GOLD SOUTHFIELD Access to Source Code and Active Development 2026-02-16 · Ransomware
Tools & malware
- ConnectWise Remote Access
- FileZilla tool
- PsExec tool
- REvil Ransomware
Vendor research
- GOLD SOUTHFIELD Secureworks
- Relentless REvil, revealed: RaaS as variable as the criminals who use it Sophos
- REvil's Grand Coup: Abusing Kaseya Managed Services Software for Massive Profits SentinelOne
- REvil/Sodinokibi Ransomware Counter Threat Unit Research Team
- REvil: The GandCrab Connection Secureworks
- The Evolution of PINCHY SPIDER from GandCrab to REvil Crowdstrike
- Secureworks. (n.d.). GOLD SOUTHFIELD Secureworks
- REvil: The GandCrab Connection Secureworks
- REvil/Sodinokibi Ransomware Secureworks