GOLD BURLAP
Objectives
Tools
SUMMARY
GOLD BURLAP is a group of financially motivated criminals responsible for the development of the Pysa ransomware, also referred to as Mespinoza. Pysa is a cross-platform ransomware with known versions written in C++ and Python. As of December 2020, approximately 50 organizations had reportedly been targeted in Pysa ransomware attacks. The operators leverage 'name and shame' tactics to apply additional pressure to victims. As of January 2021, CTU researchers had found no Pysa advertisements on underground forums, which likely indicates that it is not operated as ransomware as a service (RaaS).
A remote access trojan written in Go, which CTU researchers dubbed DNSGo, has been identified as a precursor to Pysa attacks. According to the French national cybersecurity agency, ANSSI, DNSGo has been delivered both by exploiting internet-facing devices via Remote Desktop Protocol (RDP) and by using stolen credentials. The malware has been used in conjunction with other tools, including PowerShell Empire, Advanced IP Scanner, Advanced Port Scanner, PsExec, ADRecon, Privilege Escalation Awesome Scripts Suite (PEASS), and Mimikatz.
Contact Us
Contact us directly whether your organization needs immediate assistance or you want to discuss your incident readiness, response, and testing needs.