Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Hive0065, Spandex Tempest, CHIMBORAZO, SectorJ04, SectorJ04 Group, GRACEFUL SPIDER, GOLD TAHOE, Dudear, G0092, ATK103

Description

TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.(Citation: Proofpoint TA505 Sep 2017)(Citation: Proofpoint TA505 June 2018)(Citation: Proofpoint TA505 Jan 2019)(Citation: NCC Group TA505)(Citation: Korean FSI TA505 2020)

Goals & Targeting

Targeted Sectors

Financial services
Retail
Education
Financial services
Healthcare

AI Analysis

· 1 week ago

Executive Summary

TA505 is a prolific cybercriminal group known for its dynamic malware development and ransomware campaigns targeting financial services and other sectors. The group operates with high sophistication, leveraging tools like TrickBot and Cobalt Strike to compromise organizations, aiming primarily for financial gain through activities such as data theft and ransomware deployment.

Goals & Targeting

TA505's primary objective is financial gain through activities such as ransomware deployment, data theft, and the sale of stolen information on darknet markets. The group strategically targets sectors with high-value assets, including financial services (e.g., banks, payment processors), retail (eCommerce platforms), education institutions (student databases), and healthcare organizations (patient records). Their targeting is likely influenced by the ease of access to these sectors' digital infrastructure and the potential for significant financial rewards from ransom payments or data monetization.

Enhanced Description

TA505 is a cybercriminal group active since at least 2014, renowned for its frequent changes in malware and leadership in the criminal malware distribution market. The group has notably been involved in prominent ransomware campaigns utilizing Clop ransomware. TA505 primarily targets sectors such as financial services, retail, education, and healthcare, focusing on industries with substantial financial resources or sensitive data. Their operations often involve sophisticated attack vectors, including the use of numerous malware families like TrickBot, SDBbot, FlawedGrace, and others. The group's adaptability in leveraging new tools and techniques, as evidenced by their adoption of ServHelper backdoor and lolbins for persistence and lateral movement, underscores their advanced capabilities and ability to evolve in response to operational needs and defensive measures.

Key Capabilities

  • Exploitation of unpatched vulnerabilities
  • Ransomware deployment (e.g., Clop)
  • Leverage of multi-stage malware payloads
  • Use of persistence techniques like web shells and registry modifications
  • Sophisticated spear-phishing campaigns with malicious Office documents and links
  • Fast-flux domain infrastructure for command and control communication

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Execution
Persistence
Defense Evasion
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1059.007
T1069
T1204.002
T1553.002
T1568.001
T1566.002
T1218.007
T1583.001
T1087.003
T1112
T1027.010
T1071.001
T1027.002

Software / Tooling

TrickBot
Amadey
Get2
FlawedGrace
SDBbot
Cobalt Strike
ServHelper
Clop
Dridex
Azorult

Campaigns & Victims

TA505 has been observed consistently updating their tactics and tools to remain effective. Campaigns have included the use oflolBins for persistence, new backdoor malware (e.g., ServHelper), and evolving ransomware strains like Clop. The group demonstrates a patient approach, often conducting extensive reconnaissance before deploying final payloads to maximize profitability. Notable campaigns include those targeting financial enterprises with sophisticated multi-stage attacks, leveraging web shells and native API calls for execution.

IOC Patterns

  • Spear-phishing emails with malicious Office documents or links
  • Use of Fast Flux DNS for C2 infrastructure
  • Distribution of malicious files via Rundll32, MSIEXEC, or PowerShell
  • Signatures associated with TrickBot and Cobalt Strike
  • Injection of dynamic-link libraries (DLLs) into legitimate processes

Recommended Actions

  • Implement advanced email filtering to detect spear-phishing attempts
  • Monitor for unusual RDP activity and limit access
  • Deploy endpoint detection and response (EDR) solutions
  • Regularly update software and patch vulnerabilities
  • Conduct regular training sessions on phishing awareness
  • Segment networks to limit lateral movement potential
  • Implement robust logging and monitoring for web shells and known malicious file artifacts

Suggested Tags

Cyber Crime
Ransomware
Financial Fraud
Malware Distribution Network (MDN)
Sophisticated APT-like Capabilities

Confidence Assessment

High confidence in TA505's targeting patterns and toolset, based on extensive OSINT and campaign analysis. However, the group's operational changes and adoption of new tools present challenges in complete visibility. The primary gaps are related to specific details about their internal structure and exact geographic locations.

ATT&CK Techniques

Execution
8 techniques
Stealth
8 techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 19 SHA-256 Hash 1

References

  1. Korean FSI TA505 2020 — Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.
  2. IBM TA505 April 2020 — Frydrych, M. (2020, April 14). TA505 Continues to Infect Networks With SDBbot RAT. Retrieved May 29, 2020.
  3. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  4. Proofpoint TA505 Sep 2017 — Proofpoint Staff. (2017, September 27). Threat Actor Profile: TA505, From Dridex to GlobeImposter. Retrieved May 28, 2019.
  5. Proofpoint TA505 June 2018 — Proofpoint Staff. (2018, June 8). TA505 shifts with the times. Retrieved May 28, 2019.
  6. Proofpoint TA505 Jan 2019 — Schwarz, D. and Proofpoint Staff. (2019, January 9). ServHelper and FlawedGrace - New malware introduced by TA505. Retrieved May 28, 2019.
  7. NCC Group TA505 — Terefos, A. (2020, November 18). TA505: A Brief History of Their Time. Retrieved July 14, 2022.

Intel Summary

34

Techniques

13

Tools

3

Campaigns

156

IOCs

0

Observed Data

9

Tactics

Tags

Ransomware
Cyber Crime
Financial Fraud
Malware Distribution Network (MDN)
Sophisticated APT-like Capabilities

Details

MITRE ID
G0092
Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--7eda3dd8-b09b-4705-8090-c2ad9fb8c14d
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.