GOLD DUPONT is a financially motivated cybercriminal threat group associated with operation of the RansomExx ransomware and active since at least 2018. The group has been linked to intrusions affecting organizations in multiple countries, including the United States, Canada, and Brazil, and has targeted enterprise environments with both Windows and Linux ransomware variants. Security reporting has also associated GOLD DUPONT with use of SystemBC in intrusion chains. GOLD DUPONT commonly conducts ransomware operations through multi-stage compromises that begin with phishing or malware-enabled initial access and progress rapidly to hands-on-keyboard post-compromise activity. Observed tooling associated with the group includes IcedID, Vatet loader, PyXie, Trickbot, Cobalt Strike, and RansomExx. In documented intrusions, the group used malicious macro documents and follow-on loaders to establish access, deployed beaconing frameworks for command and control, gathered host and user information, and moved laterally over SMB before ransomware execution. Reported dwell time from initial access to ransomware deployment has been as short as roughly five hours. The group’s tradecraft includes credential theft, reconnaissance, persistence through scheduled tasks, in-memory payload decryption and injection, and lateral movement across victim networks. GOLD DUPONT has used modular tooling for information gathering and payload staging prior to final ransomware deployment. Its operations have also been linked to Linux-targeting RansomExx variants designed to encrypt systems in VMware-related environments, particularly infrastructure supporting virtual machine storage, indicating an emphasis on maximizing operational disruption in enterprise networks. Aliases include golddupont and gold_dupont. GOLD DUPONT is best known for its association with RansomExx rather than a publicly attributed nation-state mission, and available information supports classification as an eCrime ransomware actor rather than a state-sponsored group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat group associated with distributing RansomExx ransomware in a separate intrusion against the same organization.
Listed as one of multiple threat groups associated with using SystemBC.
Ransomware operations associated with RansomExx, characterized by fast end-to-end intrusions (reported ~5 hours from initial access to ransomware deployment). Initial access observed via phishing leading to IcedID, followed by Vatet loader for payload delivery and post-intrusion tooling (e.g., Cobalt Strike) for C2, discovery, lateral movement, credential theft, and ultimately ransomware deployment (including a Linux variant targeting Linux/VMware-related servers).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.