GOLD SOUVENIR is the cluster name associated with former BlackSuit (Royal) members linked to the Chaos ransomware-as-a-service ecosystem, active since at least February 2025. The actor has been associated with financially motivated intrusions and ransomware deployment, including operations in which initial access was obtained through Microsoft Teams voice-phishing and social engineering that impersonated IT or helpdesk personnel. In observed campaigns, the operators persuaded users to grant remote access, then used legitimate remote administration tools, PowerShell-based payload delivery, and modular malware chains to establish footholds and expand access. Post-compromise activity has included system discovery, attempts to identify security products, persistence via user autorun mechanisms and startup shortcuts, enabling Remote Desktop Protocol on compromised hosts, deployment of custom loaders and backdoors, use of Golang-based implants, and installation of additional remote access software and reverse SOCKS proxy tooling to maintain access across victim environments. The actor has also demonstrated defense-evasion tradecraft through rapid changes to filenames, persistence artifacts, and delivery methods, as well as experimentation with DLL sideloading. Observed targeting has focused heavily on North American organizations, especially in Canada and the United States, across services, manufacturing, energy, construction and engineering, and legal organizations specializing in intellectual property. Some intrusions culminated in rapid Chaos ransomware deployment, with encryption occurring in under a day from initial access in at least one case. The available evidence supports a dominant financial motivation. While limited keyboard-layout artifacts have suggested a possible Russian-language connection, attribution to a specific national origin is not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.