ToyMaker
Gold Melody is a financially motivated cybercrime initial access broker (IAB) active since at least 2017. Known aliases include UNC961, Prophet Spider, ToyMaker, and TGR-CRI-0045; Unit 42 attributed TGR-CRI-0045 to Gold Melody with medium confidence. The group opportunistically scans and exploits internet-facing servers and public-facing applications to compromise networks and then hand off or sell that access to other actors, including ransomware operators. Reporting cited in the content links the actor to access brokerage associated with CACTUS, and earlier reporting assessed Prophet Spider likely provided access to Egregor and MountLocker operators. The actor has been observed exploiting Oracle WebLogic Server vulnerabilities, including CVE-2020-14882, CVE-2020-14750, and older issues such as CVE-2016-0545, as well as SQL injection, to gain initial access. BlackBerry also correlated Prophet Spider activity with exploitation of Log4Shell vulnerabilities in VMware Horizon. More recently, Unit 42 reported a campaign targeting Microsoft IIS servers by abusing exposed ASP.NET Machine Keys to sign malicious __VIEWSTATE payloads and achieve View State deserialization-based remote code execution. In that activity, the actor executed malicious .NET assemblies in memory, reducing on-disk artifacts. Observed post-exploitation tradecraft includes command execution from w3wp.exe, use of a consistent staging directory such as C:\Windows\Temp\111t, retrieval of tooling via curl, reflective in-memory loading of .NET modules, and use of a custom privilege-escalation tool named updf leveraging GodPotato to obtain SYSTEM and create local administrator accounts. The actor has also used TxPortMap for internal network discovery and performed reconnaissance with commands such as tasklist, ipconfig /all, quser, whoami /all, nltest /domain_trusts, net user, and systeminfo. In VMware Horizon/Log4Shell-related activity associated with Prophet Spider, reporting noted ws_TomcatService.exe spawning cmd.exe or powershell.exe, encoded PowerShell download cradles, use of C:\Windows\Temp\7fde, download of wget.bin and additional payloads, registry hive dumping for credential harvesting, webshell injection into absg-worker.js, and in some cases deployment of cryptocurrency miners or Cobalt Strike. Victims mentioned in the content include organizations in Europe and the United States across financial services, manufacturing, wholesale/retail, high technology, and transportation/logistics. The content also states that Gold Melody favors opportunistic compromise of vulnerable internet-facing infrastructure and then monetizes access through downstream criminal partners.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
4 malware families attributed to this actor across reporting.
Associated vulnerabilities
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Prophet Spider has also been seen using older Oracle CVEs such as CVE-2016-0545, as well as gaining initial access via SQL injection.
Researchers noticed a recent trend in which Prophet Spider uses CVE-2020-14882 and CVE-2020-14750 to get a foothold into target environments. Both CVEs relate to path traversal vulnerabilities that enable an attacker to access the WebLogic administrative console, which then allows for unauthenticated remote code execution.
Researchers noticed a recent trend in which Prophet Spider uses CVE-2020-14882 and CVE-2020-14750 to get a foothold into target environments. Both CVEs relate to path traversal vulnerabilities that enable an attacker to access the WebLogic administrative console, which then allows for unauthenticated remote code execution.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker activity associated with creating unauthorized user accounts and modifying Winlogon registry keys to enable automatic login and support follow-on ransomware deployment.
Initial access broker activity: scans for vulnerable systems, deploys LAGTOY/HOLERUN, and sells access to ransomware operators (e.g., CACTUS) enabling double extortion.
Gold Melody is an initial access broker who compromises ASP.NET sites using leaked machine keys and sells access to the underlying IIS servers.
Initial access broker activity exploiting leaked ASP.NET Machine Keys to perform ASP.NET View State deserialization for in-memory code execution on IIS/ASP.NET servers, followed by reconnaissance and limited post-exploitation (port scanning, privilege escalation, persistence via local admin creation).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.