Gold Dupont
GOLD DUPONT is the Secureworks-designated threat group associated with operation of the RansomExx ransomware and described as active since 2018. Reporting in the provided content links the group to RansomExx intrusions affecting organizations in the United States, Canada, and Brazil, and notes that RansomExx was responsible for several high-profile attacks in 2020. The group is described as distributing RansomExx and using a toolset that includes Vatet loader, PyXie, Trickbot, RansomExx, and Cobalt Strike. In the observed intrusion chain described in the content, initial access began with a phishing email carrying a password-protected ZIP archive containing a malicious macro-enabled Word document. Enabling macros led to download of IcedID, which was executed via regsvr32.exe, used steganography with a downloaded PNG payload, and established persistence through a scheduled task. Follow-on activity included deployment of Cobalt Strike for command-and-control, machine reconnaissance, and lateral movement over SMB. A trojanized Notepad++ binary acting as Vatet loader decrypted and executed payloads from config.dat files, including payloads used for information gathering via Pyxie, LaZagne, and Mimikatz, and ultimately for RansomExx deployment. Trend Micro reported the progression from initial access to ransomware deployment took about five hours. The content also describes newer RansomExx variants for Linux servers. A Linux RansomExx sample was analyzed as a 64-bit ELF executable using the mbedtls library for multi-threaded encryption, with no observed network activity or anti-analysis behavior. The Linux variant is described as targeting VMware-related environments, particularly systems serving as storage for VMware files, and requiring a target directory argument to begin recursive encryption and ransom note creation. Known alias in the provided content: gold_dupont.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat group associated with distributing RansomExx ransomware in a separate intrusion against the same organization.
Ransomware operations associated with RansomExx, characterized by fast end-to-end intrusions (reported ~5 hours from initial access to ransomware deployment). Initial access observed via phishing leading to IcedID, followed by Vatet loader for payload delivery and post-intrusion tooling (e.g., Cobalt Strike) for C2, discovery, lateral movement, credential theft, and ultimately ransomware deployment (including a Linux variant targeting Linux/VMware-related servers).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.