This actor typically distributes instances of the SmokeLoader intermediate downloader, which, in turn, downloads additional malware of the actor’s choice -- often banking Trojans. Figure 3 shows a lure document from a November campaign in which TA516 distributed fake resumes with malicious macros that, if enabled, launch a PowerShell script that downloads SmokeLoader. In this instance, we observed SmokeLoader downloading a Monero coinminer. Since the middle of 2017, TA516 has used similar macro-laden documents as well as malicious JavaScript hosted on Google Drive to distribute both Panda Banker and a coinminer executable via SmokeLoader, often in the same campaigns.
Executive Summary
TA516 is a persistent cyber threat actor distributing malware, primarily through malicious documents and Google Drive links. Known for using SmokeLoader as an intermediate downloader, TA516 has been active since mid-2017, targeting victims with banking Trojans and coinminers. This group's operations highlight a focus on financial gain through sophisticated yet adaptable attack techniques.
Goals & Targeting
TA516's primary goal appears to be financial enrichment through the deployment of revenue-generating malware, such as coinminers and banking Trojans. The group likely targets sectors with a high potential for financial reward, though specific sector targeting is not explicitly detailed in available intelligence, suggesting a broader or opportunistic approach. Their victims are typically individuals or organizations accessed via phishing campaigns using macro-laced documents or malicious links, making them a significant threat to businesses and consumers alike.
Enhanced Description
TA516 operates with significant persistence, employing macro-laced documents and malicious JavaScript hosted on Google Drive to distribute malware such as Panda Banker and Monero coinminers. The actor leverages SmokeLoader as a downloader for their payloads, indicating a modular approach that allows them to adapt to different threats. Despite changes in tactics over time, TA516 remains committed to campaigns designed to maximize financial gain. Their ability to combine multiple malware types within single campaigns underscores their operational flexibility and intent to exploit victims across various sectors for economic gain.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA516 has been active since mid-2017, with a notable campaign in November involving fake resumes containing malicious macros that deliver SmokeLoader and subsequently Monero coinminers. Their campaigns often combine multiple delivery methods, including macro-laced documents and Google Drive links, to distribute malware effectively.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Medium confidence in TA516's operations due to their consistent activity but limited specific campaign details beyond SmokeLoader usage. Data gaps include exact targeting sectors and countries, as well as the full range of tools and techniques employed.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics