Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: GOLD CABIN, Shathak, Shakthak, TA551, ATK236, G0127, Monster Libra

Description

TA551 is a financially-motivated threat group that has been active since at least 2018. (Citation: Secureworks GOLD CABIN) The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns. (Citation: Unit 42 TA551 Jan 2021)

AI Analysis

· 1 week ago

Executive Summary

TA551, also known as GOLD CABIN or Shathak, is a financially motivated cyber threat group active since at least 2018. They primarily distribute email-based malware targeting individuals in English, German, Italian, and Japanese speaking countries, with campaigns linked to financial gain.

Goals & Targeting

TA551's primary goal is financial gain through stealing sensitive information for fraudulent activities. They target sectors with high financial transaction volumes or valuable personal data, focusing on individuals in specific countries based on language preferences, suggesting a strategic approach to maximize their attack success rate.

Enhanced Description

TA551 operates as a financially motivated cybercriminal group known for sophisticated email-based malware campaigns. The group leverages various techniques such as standard encoding, domain generation algorithms, and malicious files to distribute their payloads. TA551 has been associated with several malware families including Ursnif, IcedID, Valak, and QakBot, which are typically used to steal financial information from targeted individuals.

Key Capabilities

  • Email-based malware distribution
  • Sophisticated encoding techniques
  • Domain generation algorithms
  • Use of known malware families

MITRE ATT&CK Tactics

Collection
Exfiltration Activities
Credential Access
Execution
Obfuscation
Impair Defensive Mechanisms
Disruption

ATT&CK Techniques

T1132.001
T1568.002
T1204.002
T1036
T1218.005
T1059.003
T1027.010
T1071.001
T1218.011
T1566.001
T1589.002
T1218.010
T1027.003

Software / Tooling

Ursnif
IcedID
Valak
QakBot

Campaigns & Victims

TA551 is known for long-term campaigns targeting individuals across multiple countries. Their operations involve sending malicious emails with attachments such as macros, scripts, or documents that execute malware upon opening. Recent campaigns include the use of Phosphorus botnet capabilities, enhancing their ability to steal banking credentials and other sensitive data.

IOC Patterns

  • Email-based spear-phishing campaigns
  • Malicious links leading to credential theft pages
  • Use of DGAs for C2 infrastructure
  • Distribution via macro-laced Office documents

Recommended Actions

  • Implement multi-layered email filtering solutions
  • Monitor for suspicious scripts and macros in emails
  • Educate users on phishing and malicious attachments
  • Regularly update endpoint protection tools

Suggested Tags

APT group
Financially motivated
Email-based threats

Confidence Assessment

High confidence due to multiple sources and linked intelligence, though some aspects like exact campaign timelines remain unclear.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Unit 42 Valak July 2020 — Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.
  2. Unit 42 TA551 Jan 2021 — Duncan, B. (2021, January 7). TA551: Email Attack Campaign Switches from Valak to IcedID. Retrieved March 17, 2021.
  3. Secureworks GOLD CABIN — Secureworks. (n.d.). GOLD CABIN Threat Profile. Retrieved March 17, 2021.

Intel Summary

14

Techniques

4

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

APT group
Financially motivated
Email-based threats

Details

MITRE ID
G0127
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--94873029-f950-4268-9cfd-5032e15cb182
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.