← Back to all threat actors

GOLD SOUTHFIELD

Also known as Pinchy Spider
Tracked as G0115

GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.

How we source and review actor profiles
Motivation
ransomware
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G0115

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Pinchy Spider

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

GOLD SOUTHFIELDCanonical Name
Pinchy SpiderAlias
G0115Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...