GOLD PRELUDEGOLD PRELUDE

Also known as: GOLD PRELUDE · TA569 · UNC1543

Known aliases
3

Profile

GOLD PRELUDE is a financially motivated cybercriminal threat group that operates the SocGholish (aka FAKEUPDATES) malware distribution network. GOLD PRELUDE operates a large global network of compromised websites, frequently running vulnerable content management systems (CMS), that redirect into a malicious traffic distribution system (TDS). The TDS, which researchers at Avast have named Parrot TDS, uses opaque criteria to select victims to serve a fake browser update page. These pages, which are customized to the specific visiting browser software, download the JavaScript-based SocGholish payload frequently embedded within a compressed archive.

Aliases· 3

GOLD PRELUDETA569UNC1543

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
FakeUpdates
Actor
GOLD CABIN
Actor
GOLD WATERFALL
Actor
GOLD FAIRFAX
Actor
GOLD GALLEON
Group
GOLD SOUTHFIELD
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.