GOLD SOUTHFIELD
Also reported as Pinchy Spider, GOLD GARDEN, PINCHY SPIDER, Gold Southfield and Gold Garden. Linked to Russia by one source.
Reports per quarter
Techniques seen in the last two years
- T1057 2 reports reports only
- T1078 2 reports reports only
- T1486 2 reports reports only
- T1489 2 reports reports only
- T1003 1 report reports only
- T1016 1 report reports only
- T1018 1 report reports only
- T1036.005 1 report reports only
- T1046 1 report reports only
- T1047 1 report reports only
Show all 25 techniques Show fewer
- T1049 1 report reports only
- T1053 1 report reports only
- T1059 1 report reports only
- T1059.004 1 report reports only
- T1070.004 1 report reports only
- T1071 1 report reports only
- T1082 1 report reports only
- T1083 1 report reports only
- T1105 1 report reports only
- T1110 1 report reports only
- T1112 1 report reports only
- T1135 1 report reports only
- T1190 1 report in ATT&CK
- T1222.002 1 report reports only
- T1490 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2003-1138
- CVE-2005-1380
- CVE-2010-0112
- CVE-2010-0738 KEV ransomware
- CVE-2010-0817
- CVE-2010-2568 KEV
- CVE-2010-2872
- CVE-2010-3936
- CVE-2011-1264
- CVE-2011-2133
- CVE-2012-2695
- CVE-2012-5687
Show all 107 CVEs Show fewer
- CVE-2013-3660 KEV
- CVE-2013-4660
- CVE-2013-5947
- CVE-2014-0552
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-3567
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0057
- CVE-2015-0554
- CVE-2015-1701 KEV ransomware
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-3082
- CVE-2016-5195 KEV
- CVE-2016-7231
- CVE-2016-7255 KEV ransomware
- CVE-2017-0068
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-14100
- CVE-2017-18362 KEV ransomware
- CVE-2017-5638 KEV ransomware
- CVE-2017-9805 KEV
- CVE-2018-0798 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-13374 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-15535
- CVE-2018-4878 KEV ransomware
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8440 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-1069 KEV ransomware
- CVE-2019-1108
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-1181
- CVE-2019-1224
- CVE-2019-1225
- CVE-2019-13720 KEV
- CVE-2019-1579 KEV ransomware
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2725 KEV ransomware
- CVE-2020-0609
- CVE-2020-0610
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-12061
- CVE-2020-1472 KEV ransomware
- CVE-2020-1664
- CVE-2020-16896
- CVE-2020-2021 KEV ransomware
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21985 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-22986 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-27101 KEV ransomware
- CVE-2021-27102 KEV ransomware
- CVE-2021-27103 KEV ransomware
- CVE-2021-27104 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-30117
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2025-68613 KEV
- CVE-2026-1731 KEV ransomware
- CVE-2026-20127 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Gandcrab (Malware Family)
-
Pinchy Spider, Gold Southfield - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Pinchy Spider, Gold Southfield - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor REvil (Malware Family)
Show all 262 reports Show fewer
-
Cause & Effect: Sodinokibi Ransomware Analysis | Tetra Defense
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Cause & Effect: Sodinokibi Ransomware Analysis | Tetra Defense
-
Scully Spider, TA547 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Scully Spider, TA547 - Threat Group Cards: A Threat Actor Encyclopedia
-
REvil Development Adds Confidence About GOLD SOUTHFIELD Reemergence
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor REvil Development Adds Confidence About GOLD SOUTHFIELD Reemergence
-
An Empirically Comparative Analysis of Ransomware Binaries
The original link failed its last check. Original publisher Detailsfor An Empirically Comparative Analysis of Ransomware Binaries
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
CARBON SPIDER Embraces Big Game Hunting, Part 2
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CARBON SPIDER Embraces Big Game Hunting, Part 2
-
ECX- Big Game Hunting on the Rise Following a Notable Reduction in Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ECX- Big Game Hunting on the Rise Following a Notable Reduction in Activity
-
REvil Ransomware Reemerges After Shutdown; Universal Decryptor Released
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor REvil Ransomware Reemerges After Shutdown; Universal Decryptor Released
-
Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
-
Hypervisor Jackpotting, Part 2- eCrime Actors Increase Targeting of ESXi Servers with Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hypervisor Jackpotting, Part 2- eCrime Actors Increase Targeting of ESXi Servers with Ransomware
-
CARBON SPIDER Embraces Big Game Hunting, Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CARBON SPIDER Embraces Big Game Hunting, Part 1
-
REvil-ution – A Persistent Ransomware Operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor REvil-ution – A Persistent Ransomware Operation
-
How CrowdStrike Falcon Stops REvil Ransomware Used in the Kaseya Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How CrowdStrike Falcon Stops REvil Ransomware Used in the Kaseya Attack
-
The Evolution of PINCHY SPIDER from GandCrab to REvil
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Evolution of PINCHY SPIDER from GandCrab to REvil
-
Update Regarding VSA Security Incident
The original link failed its last check. Original publisher Detailsfor Update Regarding VSA Security Incident
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor https://gist.githubusercontent.com/fwosar/a63e1249bfccb8395b961d3d780c0354/raw/312b2bbc566cbee2dac7b143dc143c1913ddb729/revil.json
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LV Ransomware
-
Introducing The Most Profitable Ransomware REvil
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Introducing The Most Profitable Ransomware REvil
-
Response When Minutes Matter- When Good Tools Are Used for (R)Evil
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Response When Minutes Matter- When Good Tools Are Used for (R)Evil
-
The original link failed its last check. Original publisher Detailsfor Intel 471
-
Sodinokibi REvil ransomware disrupt trade secrets
The original link failed its last check. Original publisher Detailsfor Sodinokibi REvil ransomware disrupt trade secrets
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hypervisor Jackpotting- CARBON SPIDER and SPRITE SPIDER Target ESXi Servers With Ransomware to Maximize Impact
-
Hypervisor Jackpotting - CARBON SPIDER and SPRITE SPIDER Target ESXi Servers with Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hypervisor Jackpotting - CARBON SPIDER and SPRITE SPIDER Target ESXi Servers with Ransomware
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies
-
Gaming Industry Under Attack: Darknet Threats & Leaked Data
The original link failed its last check. Original publisher Detailsfor Gaming Industry Under Attack: Darknet Threats & Leaked Data
-
Zooming into Darknet Threats Targeting Japanese Organizations
The original link failed its last check. Original publisher Detailsfor Zooming into Darknet Threats Targeting Japanese Organizations
-
Double Trouble- Ransomware with Data Leak Extortion, Part 2
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double Trouble- Ransomware with Data Leak Extortion, Part 2
-
What's behind the increase in ransomware attacks this year?
The original link failed its last check. Original publisher Detailsfor What's behind the increase in ransomware attacks this year?
-
Double Trouble- Ransomware with Data Leak Extortion, Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double Trouble- Ransomware with Data Leak Extortion, Part 1
-
Double Trouble- Ransomware with Data Leak Extortion, Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double Trouble- Ransomware with Data Leak Extortion, Part 1
-
wp-spark-state-of-ransomware.pdf
The original link failed its last check. Original publisher Detailsfor wp-spark-state-of-ransomware.pdf
-
DarkSide Pipeline Attack Shakes Up the Ransomware-as-a-Service Landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DarkSide Pipeline Attack Shakes Up the Ransomware-as-a-Service Landscape
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
2020_State-of-Malware-Report.pdf
The original link failed its last check. Original publisher Detailsfor 2020_State-of-Malware-Report.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor REvil-Sodinokibi Ransomware
-
REvil- The GandCrab Connection
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor REvil- The GandCrab Connection
-
Fake CDC Flu Pandemic Warning delivers Gandcrab 5.2 ransomware
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Fake CDC Flu Pandemic Warning delivers Gandcrab 5.2 ransomware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
PINCHY SPIDER Affiliates Adopt “Big Game Hunting” Tactics to Distribute GandCrab Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PINCHY SPIDER Affiliates Adopt “Big Game Hunting” Tactics to Distribute GandCrab Ransomware
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
Newest first. Details opens the report in Explore.