Uptime Hamster: 10d 21h 24mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza GOLD BURLAP

GOLD BURLAP

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: CYBORG SPIDER
Ver en IntelTracker → APTTrail →
GOLD BURLAP, also known as CYBORG SPIDER and Mespinoza, is a financially motivated cybercriminal group that emerged in October 2018. The group is responsible for the development and operation of the Pysa (Mespinoza) ransomware, which they first used to encrypt victim files with the .pysa extension in December 2019. Unlike some other ransomware groups, GOLD BURLAP does not operate Pysa as a Ransomware-as-a-Service (RaaS) model. The group distinguishes itself through its cross-platform Pysa ransomware, developed in both C++ and Python, and its consistent use of "name and shame" tactics via a dedicated leak site called "Pysa's Partners" to pressure victims into paying ransoms. While primarily financially driven, the group is suspected with unknown confidence to have ties to Russia. GOLD BURLAP consistently targets high-value organizations across various sectors, including finance, healthcare, and education.

Aliases del actor

CYBORG SPIDER

Actores similares

Scattered Spideractor · 2Indrik Spideractor · 1doppel-spideractor · 1salty-spideractor · 1brain-spideractor · 1skeleton-spideractor · 1bamboo-spideractor · 1andromeda-spideractor · 1cobalt-spideractor · 1boson-spideractor · 1
Tecnicas MITRE
T1505.003, T1082, T1211, T1566.001
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
29
Actualizado
Wed, 01 Ju

Sectores objetivo (SOCRadar)

Construction of BuildingsManufacturingConstructionPublic AdministrationEducational ServicesWholesale TradeEnergy & Utilities InsuranceAircraft ManufacturingChemical&Pharmaceutical Manufacturing