Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

TA547 is responsible for many other campaigns since at least November 2017. The other campaigns by the actor were often localized to countries such as Australia, Germany, the United Kingdom, and Italy. Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.

AI Analysis

· 1 week ago

Executive Summary

TA547 is a cybercriminal threat actor known for conducting campaigns targeting various sectors and countries since at least November 2017. The group primarily uses malware such as ZLoader, Gootkit, Ursnif, and others to compromise systems, often through phishing and other attack vectors.

Goals & Targeting

TA547's strategic objectives appear to be primarily financial, focusing on stealing sensitive information such as banking credentials. The group targets individuals and organizations across multiple sectors but has shown a particular interest in financially motivated compromises. Its victims are typically located in highly developed economies where online financial transactions are prevalent, making it easier to monetize stolen data.

Enhanced Description

TA547 is a moderately sophisticated cybercriminal threat actor that has been active since at least November 2017. The group primarily targets individuals and organizations in sectors such as finance, retail, and government across various countries including Australia, Germany, the United Kingdom, and Italy. TA547 is known for its use of a variety of malicious software, including ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware. The group's campaigns often involve phishing emails delivered via malicious URLs or macro-laced Office documents. TA547 has shown a preference for targeting financial institutions and individuals to steal credentials and sensitive data, which aligns with its likely goal of financial gain. Recent activity includes the use of Rhadamanthys Stealer in attacks against German organizations.

Key Capabilities

  • Phishing campaigns
  • Malware distribution (ZLoader, Gootkit, Ursnif)
  • Credential theft
  • Financial fraud

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

ZLoader
Gootkit
Ursnif
Corebot
Panda Banker
Atmos
Mazar Bot

Campaigns & Victims

TA547's campaigns have been observed targeting German organizations, likely due to the high concentration of financial institutions and individuals in those regions. The group's use of Rhadamanthys Stealer indicates a focus on sophisticated credential theft operations. TA547's operational tempo appears steady, with periodic activity over several years indicating some level of resource availability.

IOC Patterns

  • Spear-phishing emails delivering malicious URLs
  • Domain registration patterns consistent with known campaigns (e.g., indscpm.xyz)
  • IP addresses associated with command and control servers

Recommended Actions

  • Implement multi-factor authentication for financial accounts
  • Educate users on phishing email awareness
  • Monitor network traffic for known TA547-related domains and IP addresses
  • Use anti-phishing tools to detect malicious URLs

Suggested Tags

Banking Trojan
Geographically Targeted

Confidence Assessment

Moderately high confidence in the identification of TA547 as a cybercriminal threat actor, with specific campaign patterns and malware associations. Some gaps remain in understanding exact TTPs beyond known campaigns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

3

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Banking Trojan
Geographically Targeted

Details

Type
Criminal
Confidence
70%
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.