Also known as: Hive0118
TA577 functions primarily as an initial access broker (IAB) that sells or distributes a range of malware backdoors to adversaries. The actor’s catalog includes QakBot, Pikabot, and the relatively new Latrodectus strains, indicating both opportunistic use of existing high‑profile payloads and active development or acquisition of fresh threats. The group first appeared in publicly available security analysis during 2023 when it was identified as one of the earliest distributors of Latrodectus. Subsequent reports note its continued activity through at least early 2024, with evidence linking it to spear‑phishing campaigns that exploit JavaScript-based drive‑by downloads and malicious hyperlinks. TA577’s operational model revolves around the sale or transfer of compromised email accounts and pre‑packaged malware delivery kits. By providing adversaries with readily deployable tools, the actor facilitates rapid compromise with minimal technical skill required on the purchaser’s part. This broker‑style approach underscores a focus on monetization and breadth of reach rather than deep‑rooted nation‑state espionage objectives. While publicly available data does not pinpoint a national affiliation or specific strategic agenda, TA577’s use of widespread phishing vectors points to a broad, opportunistic targeting strategy aimed at any organization that can be lured via social engineering or exploited through known delivery channels.
Executive Summary
TA577, also known as Hive0118, operates as an initial access broker (IAB) that has distributed the QakBot, Pikabot, and Latrodectus malware families. First noted in 2023, the group supplies malicious payloads and compromised email accounts to buyers, facilitating entry into target networks via spear‑phishing links and embedded JavaScript. Its exact origin, sector focus, and strategic motives remain largely unidentified.
Goals & Targeting
TA577 appears motivated by commercial exploitation rather than geopolitical objectives. By distributing popular malware families such as QakBot and Pikabot, the actor targets organizations across multiple sectors—particularly those with high-value data or high connectivity that make them vulnerable to phishing vectors. The typical victims are enterprises lacking robust email security controls, making them ripe for spear‑phishing link delivery that injects JavaScript payloads into web pages. The broker’s goal is to provide adversaries with a ready‑made attack entry point, thereby increasing the likelihood of successful compromise and subsequent exploitation or resale.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first public detection in 2023, TA577 has operated on a broker model, distributing high‑profile backdoors and compromised credentials to clients worldwide. The actor’s operational tempo appears consistent, with monthly updates of new or variant malware kits distributed via short URL links and phishing email campaigns. While precise campaign targets are not known, the use of JavaScript payloads and spear‑phishing indicates a preference for web‑based compromise vectors that can reach broad audiences without specialized intrusion methods.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available information about TA577 is limited and primarily derived from its documented role as a distributor of QakBot, Pikabot, and Latrodectus. While the linked ATT&CK techniques provide concrete evidence of specific tactics, there is no detailed public data on the actor’s origin, sector focus, or high‑profile incidents involving their malware. Consequently, confidence in strategic intent and victim profiling remains low; additional intelligence from incident reports or threat feed correlations would help refine these assessments.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
6
Techniques
5
Tools
0
Campaigns
0
IOCs
0
Observed Data
4
Tactics