Cyber Resilience

Threat actor · all actors

GOLD SOUTHFIELDG0115 unknown

aka GOLD SOUTHFIELD, Pinchy Spider

Last updated: 2026-08-22

1attributed CVEs
12ATT&CK techniques
1.2IDF score (tooling uniqueness)
0exclusive CVEs
2026years active

About this actor

First observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the course of the year established a RaaS operation with a dedicated set of affiliates. CrowdStrike Intelligence has recently observed PINCHY SPIDER affiliates deploying GandCrab ransomware in enterprise environments, using lateral movement techniques and tooling commonly associated with nation-state adversary groups and penetration testing teams. This change in tactics makes PINCHY SPIDER and its affiliates the latest eCrime adversaries to join the growing trend of targeted, low-volume/high-return ransomware deployments known as “big game hunting.” PINCHY SPIDER is the criminal group behind the development of the ransomware most commonly known as GandCrab, which has been active since January 2018. PINCHY SPIDER sells access to use GandCrab ransomware under a partnership program with a limited number of accounts. The program is operated with a 60-40 split in profits (60 percent to the customer), as is common among eCrime actors, but PINCHY SPIDER is also willing to negotiate up to a 70-30 split for “sophisticated” customers.

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0115

CrowdStrikenation-animal names

Pinchy Spider

Secureworkscolour-metal names

GOLD SOUTHFIELD

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 12 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2026-20929 5.97.50.01162026-01-13see CVE

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
CM-610 / 1283%
SI-49 / 1275%
AC-38 / 1267%
CM-78 / 1267%
SI-38 / 1267%
CM-27 / 1258%
RA-57 / 1258%
SI-27 / 1258%
SI-77 / 1258%
AC-66 / 1250%
CA-76 / 1250%
AC-45 / 1242%
CM-85 / 1242%
SC-75 / 1242%
SI-105 / 1242%

Co-occurring actors

Similar actors

Overlapping CVEs