TA547 is responsible for many other campaigns since at least November 2017. The other campaigns by the actor were often localized to countries such as Australia, Germany, the United Kingdom, and Italy. Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.
Executive Summary
TA547 is a cybercriminal threat actor known for conducting campaigns targeting various sectors and countries since at least November 2017. The group primarily uses malware such as ZLoader, Gootkit, Ursnif, and others to compromise systems, often through phishing and other attack vectors.
Goals & Targeting
TA547's strategic objectives appear to be primarily financial, focusing on stealing sensitive information such as banking credentials. The group targets individuals and organizations across multiple sectors but has shown a particular interest in financially motivated compromises. Its victims are typically located in highly developed economies where online financial transactions are prevalent, making it easier to monetize stolen data.
Enhanced Description
TA547 is a moderately sophisticated cybercriminal threat actor that has been active since at least November 2017. The group primarily targets individuals and organizations in sectors such as finance, retail, and government across various countries including Australia, Germany, the United Kingdom, and Italy. TA547 is known for its use of a variety of malicious software, including ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware. The group's campaigns often involve phishing emails delivered via malicious URLs or macro-laced Office documents. TA547 has shown a preference for targeting financial institutions and individuals to steal credentials and sensitive data, which aligns with its likely goal of financial gain. Recent activity includes the use of Rhadamanthys Stealer in attacks against German organizations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA547's campaigns have been observed targeting German organizations, likely due to the high concentration of financial institutions and individuals in those regions. The group's use of Rhadamanthys Stealer indicates a focus on sophisticated credential theft operations. TA547's operational tempo appears steady, with periodic activity over several years indicating some level of resource availability.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderately high confidence in the identification of TA547 as a cybercriminal threat actor, with specific campaign patterns and malware associations. Some gaps remain in understanding exact TTPs beyond known campaigns.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
3
IOCs
0
Observed Data
0
Tactics