GOLD NORTHFIELD is a financially motivated ransomware threat actor associated with operation of the LV ransomware. The group is notable for repurposing a REvil/Sodinokibi binary rather than developing a distinct ransomware family, modifying a REvil 2.03 beta build by replacing its encrypted configuration and corresponding integrity values to create LV. Analysis indicates the actor likely edited the compiled binary directly instead of possessing REvil source code. The actor’s LV operations exhibited characteristics consistent with ransomware-as-a-service activity, including varying partner and campaign identifiers and the use of leak sites to pressure victims. GOLD NORTHFIELD used extortion tactics that combined file encryption with threats to publish stolen data, and leak sites displayed screenshots of allegedly exfiltrated victim information. Reporting also noted signs of immature or unreliable operational infrastructure. Observed tradecraft includes use of a packer to conceal the ransomware payload, RC4-encrypted embedded payload storage, in-memory execution from newly allocated executable memory, and anti-tamper bypass through recalculation of configuration integrity checks. The underlying ransomware functionality matched REvil behavior, including encryption of victim files and directing victims to payment and negotiation portals. Distribution vectors discussed in connection with LV include exposed remote access services, spam and malicious attachments, exploit-based delivery, deceptive downloads, and botnet-assisted deployment, though these mechanisms are associated with LV campaigns rather than uniquely attributable to GOLD NORTHFIELD. GOLD NORTHFIELD is best understood as an operator that adapted REvil tooling for its own ransomware and extortion campaigns under the LV name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Repurposed a REvil/Sodinokibi v2.03 beta binary by changing its configuration to create and operate LV ransomware.
Operates LV ransomware and repurposed a REvil v2.03 beta binary by replacing its configuration, likely to accelerate entry into the ransomware ecosystem and potentially launch a RaaS offering with leak sites and payment portals.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.