Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Hive0118

Description

TA577 functions primarily as an initial access broker (IAB) that sells or distributes a range of malware backdoors to adversaries. The actor’s catalog includes QakBot, Pikabot, and the relatively new Latrodectus strains, indicating both opportunistic use of existing high‑profile payloads and active development or acquisition of fresh threats. The group first appeared in publicly available security analysis during 2023 when it was identified as one of the earliest distributors of Latrodectus. Subsequent reports note its continued activity through at least early 2024, with evidence linking it to spear‑phishing campaigns that exploit JavaScript-based drive‑by downloads and malicious hyperlinks. TA577’s operational model revolves around the sale or transfer of compromised email accounts and pre‑packaged malware delivery kits. By providing adversaries with readily deployable tools, the actor facilitates rapid compromise with minimal technical skill required on the purchaser’s part. This broker‑style approach underscores a focus on monetization and breadth of reach rather than deep‑rooted nation‑state espionage objectives. While publicly available data does not pinpoint a national affiliation or specific strategic agenda, TA577’s use of widespread phishing vectors points to a broad, opportunistic targeting strategy aimed at any organization that can be lured via social engineering or exploited through known delivery channels.

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

TA577, also known as Hive0118, operates as an initial access broker (IAB) that has distributed the QakBot, Pikabot, and Latrodectus malware families. First noted in 2023, the group supplies malicious payloads and compromised email accounts to buyers, facilitating entry into target networks via spear‑phishing links and embedded JavaScript. Its exact origin, sector focus, and strategic motives remain largely unidentified.

Goals & Targeting

TA577 appears motivated by commercial exploitation rather than geopolitical objectives. By distributing popular malware families such as QakBot and Pikabot, the actor targets organizations across multiple sectors—particularly those with high-value data or high connectivity that make them vulnerable to phishing vectors. The typical victims are enterprises lacking robust email security controls, making them ripe for spear‑phishing link delivery that injects JavaScript payloads into web pages. The broker’s goal is to provide adversaries with a ready‑made attack entry point, thereby increasing the likelihood of successful compromise and subsequent exploitation or resale.

Enhanced Description

Key Capabilities

  • Distributes QakBot, Pikabot, and Latrodectus malware
  • Sells compromised email accounts for use in phishing campaigns
  • Creates spear‑phishing links containing embedded JavaScript payloads
  • Utilizes malicious links to deliver drive‑by downloads via web browsers
  • Employs obfuscated or embedded payload delivery (T1027.009)
  • Registers or leverages domains for command and control
  • Leverages Windows PowerShell / Command Shell for execution

MITRE ATT&CK Tactics

Initial Access
Execution
Command & Control

ATT&CK Techniques

T1027.009
T1059.007
T1566.002
T1586.002
T1059.003
T1204.001

Software / Tooling

QakBot
Pikabot
Latrodectus
Compromised Email Accounts

Campaigns & Victims

Since its first public detection in 2023, TA577 has operated on a broker model, distributing high‑profile backdoors and compromised credentials to clients worldwide. The actor’s operational tempo appears consistent, with monthly updates of new or variant malware kits distributed via short URL links and phishing email campaigns. While precise campaign targets are not known, the use of JavaScript payloads and spear‑phishing indicates a preference for web‑based compromise vectors that can reach broad audiences without specialized intrusion methods.

IOC Patterns

  • Spear‑phishing Links with Embedded JavaScript Payloads
  • Delivery of Malicious Web Pages via Short URLs
  • Use of Compromised Email Accounts to Launch Campaigns

Recommended Actions

  • Implement strict email filtering and block malicious URL shorteners; use DMARC, DKIM, and SPF to prevent spoofed emails.
  • Deploy user‑training focused on spear‑phishing awareness and safe browsing practices.
  • Enable endpoint detection & response solutions that detect QakBot, Pikabot or Latrodectus indicators of compromise.
  • Apply timely patches for browser and JavaScript engine vulnerabilities; disable legacy scripting features where possible.
  • Limit administrative rights and enforce least privilege to reduce the impact of discovered web‑based exploits.
  • Monitor network traffic for anomalous outbound connections to known malicious domains or repeated C2 patterns.

Suggested Tags

APT
Initial Access Broker
Malware Distribution
QakBot
Pikabot
Latrodectus
Spearfishing
Email Account Compromise

Confidence Assessment

The available information about TA577 is limited and primarily derived from its documented role as a distributor of QakBot, Pikabot, and Latrodectus. While the linked ATT&CK techniques provide concrete evidence of specific tactics, there is no detailed public data on the actor’s origin, sector focus, or high‑profile incidents involving their malware. Consequently, confidence in strategic intent and victim profiling remains low; additional intelligence from incident reports or threat feed correlations would help refine these assessments.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Latrodectus APR 2024 — Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.

Intel Summary

6

Techniques

5

Tools

0

Campaigns

0

IOCs

0

Observed Data

4

Tactics

Tags

Critical Infrastructure
APT
Initial Access Broker
Malware Distribution
QakBot
Pikabot
Latrodectus
Spearfishing
Email Account Compromise

Details

MITRE ID
G1037
Type
Unknown
Country of Origin
R
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--13ef3485-70d2-4567-b934-0e83c1eafcf1
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.