GOLD SOUTHFIELD
G0115
EASTERN EUROPE
PINCHY SPIDER
Threat IntelligenceAPTOctober 26, 2025

GOLD SOUTHFIELD Threat Profile

Ransomware group operating the REvil/Sodinokibi Ransomware-as-a-Service, responsible for Kaseya supply chain attack affecting 1,500+ businesses.

Ransomware group operating the REvil/Sodinokibi Ransomware-as-a-Service, responsible for Kaseya supply chain attack affecting 1,500+ businesses. This profile is mapped to MITRE ATT&CK G0115 and covers attribution, tooling, targeting, and defensive recommendations based on observed campaigns.

Overview & Attribution

GOLD SOUTHFIELD (also tracked as Pinchy Spider) is a threat group attributed to Eastern Europe. The group primarily targets Global, all sectors (RaaS) for intelligence collection and operational objectives aligned with state interests.

MITRE ATT&CK Reference

This group is tracked as G0115 in the MITRE ATT&CK framework. All techniques referenced in this report are mapped to ATT&CK for consistent threat modeling and detection engineering.

Arsenal & Tools

Known tools and malware associated with GOLD SOUTHFIELD include:

Targeting & Operations

GOLD SOUTHFIELD operations focus on Global, all sectors (RaaS). The group typically gains initial access through spear-phishing, exploitation of public-facing applications, or strategic web compromises before deploying custom implants for persistent access and data exfiltration.

Targeting Advisory

Organizations in the Global sector should treat GOLD SOUTHFIELD as a relevant threat and validate their detection coverage against the MITRE ATT&CK techniques listed below.

MITRE ATT&CK Mapping

Key techniques observed in GOLD SOUTHFIELD operations:

Technique IDTechnique NameTactical Context
T1486T1486Observed in GOLD SOUTHFIELD campaigns
T1195.002T1195.002Observed in GOLD SOUTHFIELD campaigns
T1190T1190Observed in GOLD SOUTHFIELD campaigns
T1059.001T1059.001Observed in GOLD SOUTHFIELD campaigns

Full ATT&CK mapping: https://attack.mitre.org/groups/G0115/

Notable Campaigns

This threat group has been active in operations targeting Global, all sectors (RaaS). Security researchers have documented campaigns involving REvil/Sodinokibi and other tools deployed against organizations in multiple countries. Attribution confidence varies by campaign, but consistent infrastructure and TTP overlap links activity to Eastern Europe-nexus operations.

Detection & Defense

Recommended defensive measures against GOLD SOUTHFIELD:

How Mjolnir Security Can Help

Defend Against GOLD SOUTHFIELD

Mjolnir Security provides tailored threat intelligence, detection engineering, and incident response services to help organizations defend against Eastern Europe-nexus threat actors.

Threat Intelligence Detection Engineering Incident Response Red Team Assessment Threat Hunting

Contact us: mjolnirsecurity.com

Written by: Mjolnir Security  |  Published: October 26, 2025