GOLD MELODY, also known as ToyMaker, Prophet Spider, and UNC961, is a financially motivated cybercrime group and initial access broker active since at least 2017. It opportunistically compromises organizations and sells or transfers access to other threat actors. Its targets include retail, health care, energy, financial services, high-technology organizations, and critical infrastructure enterprises across North America, Northern Europe, and Western Asia. The group primarily gains access by scanning for and exploiting vulnerabilities in internet-facing servers and applications, frequently using publicly available exploit code. Its exploitation history includes Oracle WebLogic, Citrix products, GitLab, Atlassian Confluence, ForgeRock AM, and Apache Log4j, including Log4Shell exploitation against VMware Horizon. SQL injection has also been observed as an initial-access technique. After compromise, GOLD MELODY conducts host, user, domain, and network reconnaissance; harvests credentials; and establishes persistent remote access. Its toolkit combines web shells, legitimate operating-system utilities, publicly available tools, proprietary backdoors, and reverse-tunneling components. Named tools include GOTROJ, also known as MUTEPUT, and LAGTOY, also known as HOLERUN. LAGTOY provides reverse-shell access, persists through a Windows service, and incorporates anti-debugging logic. Observed credential-harvesting methods include extracting sensitive registry hives and capturing host memory with Magnet RAM Capture, followed by archiving and exfiltrating memory dumps. The group also creates unauthorized local administrator accounts and uses OpenSSH components for remote access. GOLD MELODY's access-brokerage activity has preceded ransomware operations by distinct follow-on actors, including Maze, Egregor, and Cactus. Its role is establishing and transferring access rather than necessarily conducting the subsequent encryption or extortion. In a documented critical-infrastructure intrusion, ToyMaker harvested credentials and deployed LAGTOY before Cactus later entered the environment using the stolen credentials.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.
Secureworks linked Gold Melody to five intrusions between July 2020 and July 2022 involving flaws impacting Oracle E-Business Suite (CVE-2016-0545) to obtain initial access.
Gold Melody has been previously linked to attacks exploiting security flaws in Oracle WebLogic (CVE-2020-14750 and CVE-2020-14882).
Gold Melody has been previously linked to attacks exploiting security flaws in Oracle WebLogic (CVE-2020-14750 and CVE-2020-14882).
Secureworks linked Gold Melody to five intrusions between July 2020 and July 2022 involving flaws impacting Apache Struts (CVE-2017-5638) to obtain initial access.
Gold Melody has been previously linked to attacks exploiting security flaws in JBoss Messaging (CVE-2017-7504).
8 more CVEs tied to this actor tracked in Mallory.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker activity associated with creating unauthorized user accounts and modifying Winlogon registry keys to enable automatic login and support follow-on ransomware deployment.
Initial access broker activity: scans for vulnerable systems, deploys LAGTOY/HOLERUN, and sells access to ransomware operators (e.g., CACTUS) enabling double extortion.
Initial access broker providing access to secondary ransomware actors such as Cactus using a custom credential-stealing backdoor.
Gold Melody is an initial access broker who compromises ASP.NET sites using leaked machine keys and sells access to the underlying IIS servers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.