Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

TA579, a threat actor that Proofpoint researchers have been tracking since August 2021. This actor frequently delivered BazaLoader and IcedID in past campaigns.

AI Analysis

· 2 weeks ago

Executive Summary

TA579 is an active threat actor since August 2021, primarily known for deploying BazaLoader and IcedID malware. Targeting North American financial services and retail sectors, they use phishing campaigns to gain unauthorized access, aiming to steal sensitive data with financial motives.

Goals & Targeting

TA579’s primary objective appears to be financial gain through the theft of sensitive information and potential unauthorized transactions due to their targeting of financial services. By focusing on North American retail sectors, they may also seek personally identifiable information (PII) for fraudulent activities. Their victimology indicates a preference for industries rich in financial data, making them attractive targets for cybercriminal operations.

Enhanced Description

TA579 has been tracked by Proofpoint since August 2021, engaging in campaigns that deploy BazaLoader and IcedID malware. These tools are indicative of their focus on cybercrime activities, particularly targeting sectors handling financial information. The actor's operations suggest a strategic approach to selecting victims, likely for the purpose of financial gain. Their use of known malware frameworks indicates some level of operational maturity in executing campaigns, suggesting they aim to maximize the impact of their attacks within specific industries.

Key Capabilities

  • Phishing campaign orchestration
  • Deployment of BazaLoader and IcedID malware
  • Staging infrastructure setup
  • Credential theft via malware

MITRE ATT&CK Tactics

Initial Access
Execution

ATT&CK Techniques

T1566.001
T1059.003
T1584
T1064

Software / Tooling

BazaLoader
IcedID

Campaigns & Victims

TA579 has been observed leveraging phishing emails to deliver BazaLoader. Campaigns have targeted financial institutions in North America, suggesting a prolonged operational presence and focus on sectors with high financial yield potential. Their use of known malware frameworks without significant customizations may indicate reuse or purchase from other threat actors.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Command-and-control (C2) communication via established servers
  • Staging infrastructure using bulletproof hosting providers
  • Presence of IcedID and BazaLoader indicators

Recommended Actions

  • Implement email filtering to detect phishing attempts
  • Deploy endpoint detection and response solutions
  • Monitor for unusual activity in financial systems
  • Educate employees on recognizing suspicious emails

Suggested Tags

Banking Trojan
Phishing
Financial Sector

Confidence Assessment

Confidence is low due to the limited details available about TA579's exact TTPs and infrastructure. While BazaLoader and IcedID are known in the wild, specific evidence linking them directly to TA579 requires further verification.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Banking Trojan
Phishing
Financial Sector

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.