GOLD GALLEON is a suspected cybercriminal threat actor associated with the use of commodity credential-stealing malware, including HawkEye and Pony, also known as Fareit or Siplog. Available reporting links the group to financially motivated operations rather than espionage. The actor has been mentioned in connection with long-running malware ecosystems built around phishing delivery, trojanized software, and other opportunistic infection vectors. The malware associated with GOLD GALLEON supports credential theft from browsers, email clients, and FTP software, and in some cases also enables keylogging, clipboard theft, screenshot capture, cryptocurrency wallet theft, and follow-on malware delivery. Observed tradecraft in these malware families includes persistence through user autorun mechanisms and scheduled tasks, anti-analysis checks, self-deletion, process injection, and process hollowing, including abuse of legitimate .NET-related processes to conceal execution. These capabilities indicate an actor able to conduct initial access through phishing or malicious downloads, maintain persistence, evade defenses, steal credentials, and exfiltrate stolen information. GOLD GALLEON appears to operate within the broader commodity-malware cybercrime landscape rather than as a bespoke nation-state intrusion set. The currently available information directly supports association with credential theft and related post-compromise activity, but does not provide high-confidence, actor-specific targeting detail by country or industry.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.