GOLD PRELUDE, also tracked as TA0569, is a financially motivated initial access broker associated with the SocGholish (FakeUpdates) malware ecosystem. The actor is known for compromising legitimate websites and inserting lightweight JavaScript loaders that profile visiting systems, perform browser and environment checks, and present fake browser-update lures to selected victims. Execution commonly leads to follow-on payload delivery and establishment of attacker access that can be sold or transferred to other criminal operators. The group’s operations have been active since at least 2017 and are characterized by staged web-based infection chains, selective payload delivery, and infrastructure designed to support conditional redirection and victim filtering. Observed follow-on tooling associated with these operations includes Cobalt Strike, NetSupport RAT, and Python-based backdoors. The actor’s role is primarily upstream access enablement rather than final-stage monetization, and it has been linked to selling footholds to Evil Corp affiliates and other ransomware operators, including actors associated with WastedLocker and Hades. Tactically, GOLD PRELUDE demonstrates strong initial-access tradecraft through website compromise, malicious script injection, browser fingerprinting, and socially engineered fake-update prompts. Its operations also show defense-evasion and post-exploitation support characteristics through selective command-and-control behavior and delivery of remote access frameworks used by downstream actors. GOLD PRELUDE is best understood as a cybercriminal access broker that enables financially motivated intrusions and ransomware activity by providing vetted enterprise footholds to partner groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.