GOLD DUPONT
Also reported as SPRITE SPIDER, Sprite Spider and Gold Dupont.
Reports per quarter
Techniques seen in the last two years
- T1036.005 1 report
- T1057 1 report
- T1059.004 1 report
- T1070.004 1 report
- T1078 1 report
- T1082 1 report
- T1222.002 1 report
- T1486 1 report
- T1489 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2012-1516
- CVE-2012-1517
- CVE-2016-7463
- CVE-2017-4940
- CVE-2018-13379 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-5544 KEV ransomware
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-116511
Show all 30 CVEs Show fewer
- CVE-2020-11652 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-3955
- CVE-2020-3962
- CVE-2020-3969
- CVE-2020-3992 KEV ransomware
- CVE-2021-21974
- CVE-2021-21985 KEV ransomware
- CVE-2021-22040
- CVE-2021-22041
- CVE-2021-22043
- CVE-2021-22045
- CVE-2022-31705
- CVE-2025-24983 KEV
- CVE-2025-29814
- CVE-2025-29824 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Sprite Spider, Gold Dupont - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Sprite Spider, Gold Dupont - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PyXie (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DarkSide (Malware Family)
-
The original link failed its last check. Original publisher Detailsfor RansomExx upgrades Rust
Show all 45 reports Show fewer
-
Ransomware Spotlight RansomEXX - Security News
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Spotlight RansomEXX - Security News
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Strange Link Between A Destructive Malware And A Ransomware-Gang Linked Custom Loader- IsaacWiper Vs Vatet
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
Hypervisor Jackpotting, Part 2- eCrime Actors Increase Targeting of ESXi Servers with Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hypervisor Jackpotting, Part 2- eCrime Actors Increase Targeting of ESXi Servers with Ransomware
-
The original link failed its last check. Original publisher Detailsfor Intel 471
-
Ransomware Preparedness- A Call to Action
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Preparedness- A Call to Action
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hypervisor Jackpotting- CARBON SPIDER and SPRITE SPIDER Target ESXi Servers With Ransomware to Maximize Impact
-
Hypervisor Jackpotting - CARBON SPIDER and SPRITE SPIDER Target ESXi Servers with Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hypervisor Jackpotting - CARBON SPIDER and SPRITE SPIDER Target ESXi Servers with Ransomware
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
Expanding Range and Improving Speed- A RansomExx Approach
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Expanding Range and Improving Speed- A RansomExx Approach
-
When Threat Actors Fly Under the Radar: Vatet, PyXie and Defray777
The original link failed its last check. Original publisher Detailsfor When Threat Actors Fly Under the Radar: Vatet, PyXie and Defray777
-
When Threat Actors Fly Under the Radar- Vatet, PyXie and Defray777
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor When Threat Actors Fly Under the Radar- Vatet, PyXie and Defray777
Newest first. Details opens the report in Explore.