Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Storm-0900, UNC4122, an initial access broker, tracked as, Medicare.gov, if macros were enabled, Quishing, EtterSilent

Description

TA584 is a sophisticated threat actor that leverages compromised legitimate accounts in large waves to achieve initial access across multiple industries—including government, finance, education, manufacturing, and defense—across Europe, North America, and Asia. Their campaigns are characterized by rapid turnover; each wave lasts only days or weeks before the actor shifts tactics, lures, and infrastructure to evade detection. Core TTPs include social engineering through brand impersonation, customizable physical mail imagery, and macro‑enabled Excel documents that embed downloader scripts or remote PowerShell instructions. TA584 frequently employs ClickFix—a popular commercial social‑engineering platform—to craft custom phishing emails with localized content and spoofed display names derived from the compromised sender accounts. The actor’s delivery infrastructure is deliberately obfuscated: URLs are routed through third‑party redirect chains or TDS filtering services (e.g., Cookie Reloaded, Keitaro), use Amazon S3 buckets or Blogspot domains for final payload hosting, and dynamically change query parameters to defeat signature‑based blocking. New malware families—Tsundere Bot, a versatile backdoor with ransomware primitives, and XWorm with the "P0WER" configuration—have been introduced in 2025. TA584 also harnesses a catalog of exploitation tools such as Mimikatz for credential theft, certutil for benign-looking payload fetching, and PsExec for lateral movement. The actor’s campaigns maintain a consistent financial objective: rapid credential acquisition and opportunistic ransomware‑delivery, often targeting high‑profile entities to maximize the perceived value of stolen data. By exploiting compromised accounts, they reduce friction and avoid direct attribution, while their modular toolset enables quick adaptation to security postures and emerging defensive controls.

Goals & Targeting

Targeted Sectors

Government
Financial services
Think tank
Pharmaceutical
Construction
Education
Manufacturing
Nuclear
Defense
Media

Targeted Countries / Regions

DE
GB
AU
US
PL
RU
JP

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 9 hours ago

Executive Summary

TA584, also known as Storm‑0900 and UNC4122, is a high-volume initial access broker that targets a broad range of sectors worldwide using macro‑enabled Office attachments, brand impersonation, and rapid campaign churn. The group recently added the Tsundere Bot malware family and expanded its geographic scope to include Germany and Australia while maintaining operations in North America. Financial gain remains the primary motivation, with attacks designed for quick credential harvests and potential ransomware delivery.

Goals & Targeting

TA584’s strategic objective is primarily financial gain through large‑scale credential theft, phishing‑based initial compromise, and opportunistic ransomware deployments. The actor targets a diversified portfolio of sectors—including government agencies, defense contractors, educational institutions, media outlets, and healthcare providers—to maximize attack surface and potential payout. Geographically, TA584 has maintained a presence in the United States and Europe while recently expanding operations to Australia, Germany, Poland, Russia, Japan, and other markets. By rapidly rotating brand lures, localized content, and delivery vectors, the group avoids pattern recognition and increases the likelihood of successful compromise across diverse organizations.

Enhanced Description

Key Capabilities

  • email-based phishing
  • social engineering
  • brand impersonation with localized content
  • macro‑enabled Office documents for initial delivery
  • ClickFix social engineering platform use
  • customized physical mail imagery to increase believability
  • rapid campaign churn with short lifespans
  • delivery via compromised legitimate accounts (hundreds per wave)
  • redirect chains and intermediary landing pages to obscure final payload location
  • compromised domains
  • Amazon S3 URL hosting
  • Blogspot URLs in lure content
  • TDS filtering services such as Cookie Reloaded, Keitaro, 404
  • geographic targeting strategy with rotational focus on specific regions
  • fake video game installers and web injects via RMMs
  • backdoor loader with potential ransomware capabilities
  • impersonates legitimate entities (e.g., ADP) in phishing emails
  • email lure attacks

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion

ATT&CK Techniques

T1557
T1583
T1543
T1133
T1114
T1547
T1564
T1115
T1071
T1005
T1140
T1190
T1555
T1567
T1589
T1560
T1185
T1021
T1217
T1059
T1020
T1083
T1568
T1074
T1584
T1586
T1584.005
T1657
T1480
T1041
T1591
T1098
T1678
T1546
T1685
T1132
T1585
T1136
T1587
T1686
T1566
T1566.001
T1566.002
T1566.003
T1204
T1105
T1071.001

Software / Tooling

ClickFix
Tsundere Bot
XWorm
Ursnif
Cobalt Strike
DCRAT
Mimikatz
certutil
PsExec

Campaigns & Victims

TA584’s campaign cadence demonstrates a high‑volume, hit‑and‑miss approach: each wave harnesses thousands of compromised legitimate accounts to distribute macro‑enabled email attachments and malicious URLs. Attackers rotate brand identities daily or weekly, localizing content linguistically to match targeted regions and ensuring that the same host appears fresh with every new phishing burst. The group’s infrastructure layers include third‑party TDS services, cloud storage on Amazon S3, and user‑generated Blogspot pages, all fed through redirect chains that dynamically change query strings—a tactic that hampers static IOC correlation. Notable operations have seen the actor impersonate well‑known payroll service ADP or use customized physical mail photos to increase realism. The new Tsundere Bot and XWorm variants hint at a strategic shift toward ransomware payloads, suggesting an escalation in monetary focus while maintaining low cost of acquisition via compromised accounts.

IOC Patterns

  • customized physical mail photo attachments including recipient name and address
  • email addresses from compromised individual senders with multiple display names per campaign matching lure content
  • landing page design per campaign using distinct brands and localized languages
  • short-lived brand usage in email content to target specific geographies
  • URL download URLs with unique query strings (e.g., domain.tld/bbb/[unique_query])
  • Use of Amazon S3 bucket URLs
  • Blogspot domain references
  • Third‑party TDS services such as Cookie Reloaded, Keitaro, 404
  • Redirect chains through compromised domains
  • Dynamic URL changes per campaign
  • spoofed ADP email addresses
  • email lure attack

Recommended Actions

  • Monitor and correlate sender domains, display names, and delivery infrastructure for anomalous patterns rather than relying solely on static content filters
  • Implement user awareness training focused on brand impersonation and customized mail images
  • Deploy multi‑layered email security (attachment sandboxing, link scanning, reputation checks) to detect malicious URLs or docs from compromised accounts
  • Track distribution of Tsundere Bot across endpoints and block known indicator signatures
  • Use holistic campaign analysis tools that assess sender behaviour, infrastructure, and downstream execution
  • Disable or tightly control macros in corporate Office environments
  • Implement URL filtering and reputation checks for suspicious domains (e.g., AWS S3, Blogspot, TDS providers), Enforce email gateway scanning for spearphishing attachments and embedded redirect chains
  • Monitor endpoints for indicators of XWorm or Tsundere Bot activity, including backdoor connections and potential ransomware behaviour

Suggested Tags

TA584
Initial Access Broker
Phishing
Email-based Attack
Social Engineering
Brand Impersonation
ClickFix
Tsundere Bot
High Campaign Churn
Localized Targeting
Customized Physical Mail
macro-enabled-excel
redirect-chain
aws-s3-url
blogspot-url
tds-filter
xworm
cobalt-strike
ettersilent
storm-0900
unc4122
ADP Impersonation
Email Lure Attack

Confidence Assessment

Confidence in the core TTPs, malware families, and campaign patterns is high due to multiple independent reports and corroborating IOC evidence. However, specific attribution timelines, precise infrastructure ownership (e.g., exact compromised domain catalogs), and definitive proof of ransomware delivery attempts remain partially inferred, leaving gaps in fully mapping operational footprints across all known campaigns.

ATT&CK Techniques

Impact
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 2 Domain 7 SHA-256 Hash 2 URL 1 IPv4 Address 7 Email Address 1

References

  1. www.proofpoint.com — Cited by web research for: if macros were enabled
  2. attack.mitre.org — Cited by web research for: T1098
  3. https://www.proofpoint.com — Cited by AI analysis.
  4. https://unit42.mandiant.com — Cited by AI analysis.
  5. https://fireeye.com — Cited by AI analysis.

Intel Summary

47

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

15

Tactics

Tags

Critical Infrastructure
Initial Access Broker
Cyber Crime
Malware Distribution
Global Campaign
TA584
Phishing
Email-based Attack
Social Engineering
Brand Impersonation
ClickFix
Tsundere Bot
High Campaign Churn
Localized Targeting
Customized Physical Mail
macro-enabled-excel
redirect-chain
aws-s3-url
blogspot-url
tds-filter
xworm
cobalt-strike
ettersilent
storm-0900
unc4122
ADP Impersonation
Email Lure Attack

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
North Korea (KP)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.