Skip to main content
Mallory
8 malware families

Gold Dupont

Also known asgold_dupont

GOLD DUPONT is the Secureworks-designated threat group associated with operation of the RansomExx ransomware and described as active since 2018. Reporting in the provided content links the group to RansomExx intrusions affecting organizations in the United States, Canada, and Brazil, and notes that RansomExx was responsible for several high-profile attacks in 2020. The group is described as distributing RansomExx and using a toolset that includes Vatet loader, PyXie, Trickbot, RansomExx, and Cobalt Strike. In the observed intrusion chain described in the content, initial access began with a phishing email carrying a password-protected ZIP archive containing a malicious macro-enabled Word document. Enabling macros led to download of IcedID, which was executed via regsvr32.exe, used steganography with a downloaded PNG payload, and established persistence through a scheduled task. Follow-on activity included deployment of Cobalt Strike for command-and-control, machine reconnaissance, and lateral movement over SMB. A trojanized Notepad++ binary acting as Vatet loader decrypted and executed payloads from config.dat files, including payloads used for information gathering via Pyxie, LaZagne, and Mimikatz, and ultimately for RansomExx deployment. Trend Micro reported the progression from initial access to ransomware deployment took about five hours. The content also describes newer RansomExx variants for Linux servers. A Linux RansomExx sample was analyzed as a 64-bit ELF executable using the mbedtls library for multi-threaded encryption, with no observed network activity or anti-analysis behavior. The Linux variant is described as targeting VMware-related environments, particularly systems serving as storage for VMware files, and requiring a target directory argument to begin recursive encryption and ransom note creation. Known alias in the provided content: gold_dupont.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics28 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.001
Spearphishing Attachment
TA0002
Execution
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.005
Visual Basic
T1204
User Execution
T1204.002
Malicious File
TA0003
Persistence
1 technique
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
TA0004
Privilege Escalation
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1055
Process Injection
TA0005
Stealth
4 techniques
T1027
Obfuscated Files or Information
T1027.003
Steganography
T1036
Masquerading
T1055
Process Injection
T1218
System Binary Proxy Execution
T1218.010
Regsvr32
TA0006
Credential Access
1 technique
T1003
OS Credential Dumping
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.002
SMB/Windows Admin Shares
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1105
Ingress Tool Transfer
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
TA0040
Impact
1 technique
T1486
Data Encrypted for Impact
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping16

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal8

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

Gold Dupont | Mallory