GOLD DUPONT, also written as GoldDupont, is a financially motivated cybercriminal threat group active since at least 2018 and associated with operating and distributing RansomExx ransomware. It has compromised organizations in the United States, Canada, and Brazil. Its ransomware operations encompass Windows and Linux environments, including systems storing VMware virtual-machine files. The group's intrusion toolset includes IcedID, Vatet loader, Pyxie, TrickBot, Cobalt Strike, and SystemBC. Observed initial-access methods include phishing attachments containing macro-enabled Word documents and access through Citrix infrastructure. In one campaign, a password-protected archive delivered a malicious document that installed IcedID, followed by post-compromise tooling and ransomware deployment within approximately five hours. The intrusion used scheduled-task persistence, steganographic payload delivery, and in-memory code injection. A trojanized Notepad++ application served as Vatet loader to decrypt and execute additional payloads. Post-compromise activity included host reconnaissance, credential-gathering tools such as LaZagne and Mimikatz, and lateral movement over SMB. RansomExx variants associated with the operation encrypt files on Windows and Linux systems. Linux variants use multithreaded encryption and have targeted VMware-related storage, enabling disruption of virtualized environments. GOLD DUPONT remained associated with RansomExx intrusions in 2023.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat group associated with distributing RansomExx ransomware in a separate intrusion against the same organization.
Distributes RansomExx ransomware. It separately targeted an organization previously attacked by a LockBit affiliate, also accessing a Citrix server. The report considers common affiliate attribution unlikely because the TTPs differed significantly.
Listed as one of multiple threat groups associated with using SystemBC.
Ransomware operations associated with RansomExx, characterized by fast end-to-end intrusions (reported ~5 hours from initial access to ransomware deployment). Initial access observed via phishing leading to IcedID, followed by Vatet loader for payload delivery and post-intrusion tooling (e.g., Cobalt Strike) for C2, discovery, lateral movement, credential theft, and ultimately ransomware deployment (including a Linux variant targeting Linux/VMware-related servers).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.