Emotet, tracked by Secureworks as GOLD CRESTWOOD, is a financially motivated cybercrime operation centered on the Emotet botnet. It has functioned as a malware delivery and access-enablement ecosystem that collaborates with other major criminal groups. High-confidence reporting places Emotet in regular communication with operators associated with Conti, TrickBot, LockBit, and IcedID-linked clusters, reflecting its role in a mature, cooperative cybercrime marketplace. Emotet has been used to provide second-stage malware delivery for other financially motivated operations. Documented activity includes its use to distribute follow-on payloads in support of Dridex-related campaigns run by Evil Corp. This places GOLD CRESTWOOD primarily in the initial-access and malware-delivery portion of the intrusion chain rather than as a ransomware brand itself in the supplied facts. Known aliases include GOLD CRESTWOOD and Emotet. The available information directly supports Emotet’s role as a botnet-enabled access and payload distribution service within the broader eCrime ecosystem, but does not provide high-confidence attribution to a specific country, victim-country set, or industry focus in this dataset.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a separate threat group whose representatives frequently communicated with Stern and members of GOLD ULRICK and GOLD BLACKBURN.
Referenced as the operator of the Emotet botnet used in Dridex distribution chains.
Referenced as the operator of the Emotet botnet used in Dridex distribution chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.