GOLD CRESTWOOD is the Secureworks designation for the Emotet cybercrime operation. Emotet is a financially motivated malware ecosystem centered on a botnet used to distribute additional payloads for other criminal actors. It has functioned as a malware delivery service within a broader collaborative cybercrime environment and has been observed providing second-stage downloads to other groups, including support for downstream malware deployment. Communications exposed from the Conti/TrickBot criminal milieu showed representatives of GOLD CRESTWOOD interacting frequently with members of GOLD ULRICK and GOLD BLACKBURN, indicating operational relationships with other major financially motivated intrusion and ransomware actors. High-confidence reporting in the supplied material specifically ties GOLD CRESTWOOD to operation of the Emotet botnet and to use of that botnet as a distribution channel for follow-on malware. No additional high-confidence details on its victimology, geography, or internal sub-groups are directly supported here beyond its identification as Emotet and its role in malware distribution within the cybercrime ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a separate threat group whose representatives frequently communicated with Stern and members of GOLD ULRICK and GOLD BLACKBURN.
Referenced as the operator of the Emotet botnet used in Dridex distribution chains.
Referenced as the operator of the Emotet botnet used in Dridex distribution chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.