GOLD PRELUDEGOLD PRELUDE

Also known as: TA569 · UNC1543 · GOLD PRELUDE

Known aliases
3

Profile

GOLD PRELUDE is a financially motivated cybercriminal threat group that operates the SocGholish (aka FAKEUPDATES) malware distribution network. GOLD PRELUDE operates a large global network of compromised websites, frequently running vulnerable content management systems (CMS), that redirect into a malicious traffic distribution system (TDS). The TDS, which researchers at Avast have named Parrot TDS, uses opaque criteria to select victims to serve a fake browser update page. These pages, which are customized to the specific visiting browser software, download the JavaScript-based SocGholish payload frequently embedded within a compressed archive.

Aliases· 3

TA569UNC1543GOLD PRELUDE

References

  1. https://www.secureworks.com/research/threat-profiles/gold-prelude

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
FakeUpdates
Actor
GOLD CABIN
Actor
GOLD WATERFALL
Actor
GOLD FAIRFAX
Actor
GOLD GALLEON
Actor
GOLD DUPONT
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.