Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: APT28, Pawn Storm, Fancy Bear, Sednit, Snake, BokBot, Asylum Ambuscade, ClickFix, malvertising, quishing, UNC961, UNC1860, Scarred Manticore, Storm-0861

Description

TA571 is a spam distributor actor known for delivering a variety of malware, including DarkGate, NetSupport RAT, and information stealers. They use phishing emails with macro-enabled attachments to spread malicious PDFs containing rogue OneDrive links. TA571 has been observed using unique filtering techniques with intermediary "gates" to target specific users and bypass automated sandboxing. Proofpoint assesses with high confidence that TA571 infections can lead to ransomware.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Critical infrastructure
Transportation
Media
Entertainment

Targeted Countries / Regions

BR
IR
AU
IL

AI Analysis

No AI analysis yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 1 URL 4 SHA-256 Hash 2 Filename 3 Domain 10

References

  1. redcanary.com — Cited by web research for: ClickFix
  2. blog.talosintelligence.com — Cited by web research for: UNC961
  3. attack.mitre.org — Cited by web research for: T1059
  4. www.proofpoint.com — Cited by web research for: STOP
  5. www.proofpoint.com — Cited by web research for: CASTLELOADER

Intel Summary

17

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

5

Tactics

Tags

Ransomware
Phishing

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.