Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

This actor typically distributes instances of the SmokeLoader intermediate downloader, which, in turn, downloads additional malware of the actor’s choice -- often banking Trojans. Figure 3 shows a lure document from a November campaign in which TA516 distributed fake resumes with malicious macros that, if enabled, launch a PowerShell script that downloads SmokeLoader. In this instance, we observed SmokeLoader downloading a Monero coinminer. Since the middle of 2017, TA516 has used similar macro-laden documents as well as malicious JavaScript hosted on Google Drive to distribute both Panda Banker and a coinminer executable via SmokeLoader, often in the same campaigns.

AI Analysis

· 1 week ago

Executive Summary

TA516 is a persistent cyber threat actor distributing malware, primarily through malicious documents and Google Drive links. Known for using SmokeLoader as an intermediate downloader, TA516 has been active since mid-2017, targeting victims with banking Trojans and coinminers. This group's operations highlight a focus on financial gain through sophisticated yet adaptable attack techniques.

Goals & Targeting

TA516's primary goal appears to be financial enrichment through the deployment of revenue-generating malware, such as coinminers and banking Trojans. The group likely targets sectors with a high potential for financial reward, though specific sector targeting is not explicitly detailed in available intelligence, suggesting a broader or opportunistic approach. Their victims are typically individuals or organizations accessed via phishing campaigns using macro-laced documents or malicious links, making them a significant threat to businesses and consumers alike.

Enhanced Description

TA516 operates with significant persistence, employing macro-laced documents and malicious JavaScript hosted on Google Drive to distribute malware such as Panda Banker and Monero coinminers. The actor leverages SmokeLoader as a downloader for their payloads, indicating a modular approach that allows them to adapt to different threats. Despite changes in tactics over time, TA516 remains committed to campaigns designed to maximize financial gain. Their ability to combine multiple malware types within single campaigns underscores their operational flexibility and intent to exploit victims across various sectors for economic gain.

Key Capabilities

  • Distribution of SmokeLoader downloader
  • Use of malicious macros in document attacks
  • Hosted malware on Google Drive for delivery
  • Deployment of banking Trojans and coinminers
  • Combination of multiple payloads in single campaigns

MITRE ATT&CK Tactics

Defense Evasion
Disruption
Exfiltration Techniques
System Access
Collection
Lateral Movement
Credential Access

ATT&CK Techniques

T1059
T1204.001
T1066

Software / Tooling

SmokeLoader
Panda Banker
Monero Coinminer

Campaigns & Victims

TA516 has been active since mid-2017, with a notable campaign in November involving fake resumes containing malicious macros that deliver SmokeLoader and subsequently Monero coinminers. Their campaigns often combine multiple delivery methods, including macro-laced documents and Google Drive links, to distribute malware effectively.

IOC Patterns

  • Spear-phishing emails with malicious macros
  • Malicious JavaScript files hosted on Google Drive
  • Delivery of SmokeLoader as an intermediate downloader

Recommended Actions

  • Improve email filtering to detect and block malicious attachments
  • Monitor for suspicious PowerShell activity indicative of SmokeLoader execution
  • Implement strict policies against enabling macros in untrusted documents
  • Enhance endpoint detection capabilities to spot malicious download activities
  • Regularly update and patch systems to mitigate known vulnerabilities

Suggested Tags

APT
banking Trojan
malware distribution
financial gain

Confidence Assessment

Medium confidence in TA516's operations due to their consistent activity but limited specific campaign details beyond SmokeLoader usage. Data gaps include exact targeting sectors and countries, as well as the full range of tools and techniques employed.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
APT
banking Trojan
malware distribution
financial gain

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.