GOLD LAGOON is a financially motivated cybercriminal threat group associated with operation of the Qakbot botnet since at least 2007. The group uses Qakbot as an access and delivery platform, frequently deploying Cobalt Strike onto infected hosts, particularly systems joined to Active Directory domains. GOLD LAGOON activity is linked to intrusion chains that begin with phishing-delivered malware infection, followed by host profiling, command-and-control communications, deployment of secondary tooling, and hands-on-keyboard post-compromise operations. The group has used Cobalt Strike for remote code execution, reconnaissance, remote system discovery, domain account discovery, lateral movement over SMB and administrative shares, and persistence through Windows service creation. Observed tradecraft also includes use of Rundll32 for proxy execution, PowerShell stagers for in-memory payload execution, and process memory injection. GOLD LAGOON has been observed enabling downstream ransomware operations by providing access into compromised environments, and its intrusions have culminated in ransomware deployment including REvil in at least one documented case. GOLD LAGOON is best characterized as an access-oriented financially motivated actor that combines botnet operations with post-exploitation tooling to expand within victim networks and facilitate monetization through ransomware and related criminal activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated threat group operating the Qakbot malware/botnet, which supports numerous capabilities including facilitating ransomware attacks.
Financially motivated intrusion activity using Qakbot to deploy Cobalt Strike, followed by lateral movement, persistence, reconnaissance, and enabling post-intrusion ransomware attacks by providing access to other ransomware-deploying groups.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.