Also known as: Hive0065, Spandex Tempest, CHIMBORAZO, SectorJ04, SectorJ04 Group, GRACEFUL SPIDER, GOLD TAHOE, Dudear, G0092, ATK103
TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.(Citation: Proofpoint TA505 Sep 2017)(Citation: Proofpoint TA505 June 2018)(Citation: Proofpoint TA505 Jan 2019)(Citation: NCC Group TA505)(Citation: Korean FSI TA505 2020)
Targeted Sectors
Executive Summary
TA505 is a prolific cybercriminal group known for its dynamic malware development and ransomware campaigns targeting financial services and other sectors. The group operates with high sophistication, leveraging tools like TrickBot and Cobalt Strike to compromise organizations, aiming primarily for financial gain through activities such as data theft and ransomware deployment.
Goals & Targeting
TA505's primary objective is financial gain through activities such as ransomware deployment, data theft, and the sale of stolen information on darknet markets. The group strategically targets sectors with high-value assets, including financial services (e.g., banks, payment processors), retail (eCommerce platforms), education institutions (student databases), and healthcare organizations (patient records). Their targeting is likely influenced by the ease of access to these sectors' digital infrastructure and the potential for significant financial rewards from ransom payments or data monetization.
Enhanced Description
TA505 is a cybercriminal group active since at least 2014, renowned for its frequent changes in malware and leadership in the criminal malware distribution market. The group has notably been involved in prominent ransomware campaigns utilizing Clop ransomware. TA505 primarily targets sectors such as financial services, retail, education, and healthcare, focusing on industries with substantial financial resources or sensitive data. Their operations often involve sophisticated attack vectors, including the use of numerous malware families like TrickBot, SDBbot, FlawedGrace, and others. The group's adaptability in leveraging new tools and techniques, as evidenced by their adoption of ServHelper backdoor and lolbins for persistence and lateral movement, underscores their advanced capabilities and ability to evolve in response to operational needs and defensive measures.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA505 has been observed consistently updating their tactics and tools to remain effective. Campaigns have included the use oflolBins for persistence, new backdoor malware (e.g., ServHelper), and evolving ransomware strains like Clop. The group demonstrates a patient approach, often conducting extensive reconnaissance before deploying final payloads to maximize profitability. Notable campaigns include those targeting financial enterprises with sophisticated multi-stage attacks, leveraging web shells and native API calls for execution.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in TA505's targeting patterns and toolset, based on extensive OSINT and campaign analysis. However, the group's operational changes and adoption of new tools present challenges in complete visibility. The primary gaps are related to specific details about their internal structure and exact geographic locations.
TA505 Group’s TeslaGun In-Depth Analysis
Imported from MISP event #324 (9db70e24-8bd4-4b1e-a13a-cd82cefb6947).
Sep 12, 2022
TLP:CLEARNo observed data linked yet.
34
Techniques
13
Tools
3
Campaigns
156
IOCs
0
Observed Data
9
Tactics