Skip to content

Hide Navigation Hide TOC

GOLD PRELUDE (8134c96d-d6ed-49cc-99d6-fe74c0636387)

GOLD PRELUDE is a financially motivated cybercriminal threat group that operates the SocGholish (aka FAKEUPDATES) malware distribution network. GOLD PRELUDE operates a large global network of compromised websites, frequently running vulnerable content management systems (CMS), that redirect into a malicious traffic distribution system (TDS). The TDS, which researchers at Avast have named Parrot TDS, uses opaque criteria to select victims to serve a fake browser update page. These pages, which are customized to the specific visiting browser software, download the JavaScript-based SocGholish payload frequently embedded within a compressed archive.

Cluster A Galaxy A Cluster B Galaxy B Level
FakeUpdates (cd32b19e-c365-4efc-9998-548e50e04a4c) Tool GOLD PRELUDE (8134c96d-d6ed-49cc-99d6-fe74c0636387) Threat Actor 1
FAKEUPDATES (cff35ce3-8d6f-417b-ae6c-a9e6a60ee26c) Malpedia FakeUpdates (cd32b19e-c365-4efc-9998-548e50e04a4c) Tool 2