GOLD DUPONT is the Secureworks-designated threat group associated with operation of the RansomExx ransomware and has been active since at least 2018. The group is financially motivated and has conducted ransomware intrusions against organizations in North and South America, with confirmed victim geography including the United States, Canada, and Brazil. RansomExx activity attributed to GOLD DUPONT has included both Windows and Linux tooling, with Linux variants adapted to target server environments associated with VMware storage and virtualization infrastructure. GOLD DUPONT intrusions have used a multi-stage toolchain that includes phishing-delivered malware for initial access, followed by loaders and post-compromise frameworks that accelerate movement to ransomware deployment. Observed operations used IcedID as an initial access vector, Vatet loader for payload delivery, and PyXie together with Cobalt Strike for post-intrusion activity. Reported arsenals associated with the group also include Trickbot and SystemBC. In one documented intrusion chain, the operation progressed from phishing to ransomware execution in roughly five hours. The group’s tradecraft includes initial access, persistence, reconnaissance, lateral movement, exfiltration, and post-exploitation. Observed behavior includes malicious macro-enabled document delivery, scheduled-task persistence, execution through signed Windows utilities, in-memory payload decryption and injection, host information collection, SMB-based lateral movement, and use of Cobalt Strike for command-and-control and follow-on operations. SystemBC has also been associated with GOLD DUPONT activity, indicating use of proxying/backdoor capability in some intrusion sets. RansomExx malware linked to GOLD DUPONT is notable for cross-platform capability. Linux variants have been documented as focused encryptors that recursively process specified directories and are suited to disrupting VMware-related environments by targeting systems that store virtual machine data. This aligns with the group’s broader pattern of enterprise-focused ransomware operations designed to maximize operational impact.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat group associated with distributing RansomExx ransomware in a separate intrusion against the same organization.
Listed as one of multiple threat groups associated with using SystemBC.
Ransomware operations associated with RansomExx, characterized by fast end-to-end intrusions (reported ~5 hours from initial access to ransomware deployment). Initial access observed via phishing leading to IcedID, followed by Vatet loader for payload delivery and post-intrusion tooling (e.g., Cobalt Strike) for C2, discovery, lateral movement, credential theft, and ultimately ransomware deployment (including a Linux variant targeting Linux/VMware-related servers).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.