GOLD SOUTHFIELDGOLD SOUTHFIELD
Also known as: GOLD SOUTHFIELD
Known aliases
1
Profile
GOLD SOUTHFIELD is a financially motivated cybercriminal threat group that authors and operates the REvil (aka Sodinokibi) ransomware on behalf of various affiliated threat groups. Operational since April 2019, the group obtained the GandCrab source code from GOLD GARDEN, the operators of GandCrab that voluntarily withdrew their ransomware from underground markets in May 2019. GOLD SOUTHFIELD is responsible for authoring REvil and operating the backend infrastructure used by affiliates (also called partners) to create malware builds and to collect ransom payments from victims. CTU researchers assess with high confidence that GOLD SOUTHFIELD is a former GandCrab affiliate and continues to work with other former GandCrab affiliates.
Aliases· 1
GOLD SOUTHFIELD
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.