Also known as: DEV-0450
One of the most active Qbot malware affiliates, Proofpoint has tracked the large cybercrime threat actor TA570 since 2018.
Executive Summary
TA570, also known as DEV-0450, is a prominent cybercrime threat actor associated with the Qbot malware family. Active since at least 2018, TA570 has been linked to several high-profile campaigns targeting financial institutions and other industries. The group primarily relies on banking Trojans and phishing activities to achieve its objectives, making it a significant threat to global enterprises.
Goals & Targeting
TA570's strategic objectives appear to be primarily financially motivated, focusing on extracting sensitive information such as banking credentials and facilitating unauthorized transactions. The group's targeting profile includes financial institutions, retail sectors, and other organizations with accessible financial systems. TA570 often uses phishing campaigns and malware distribution to gain initial access to victim networks, enabling subsequent lateral movement and data exfiltration.
Enhanced Description
TA570 is one of the most active affiliates in the Qbot malware ecosystem, known for its sophisticated banking Trojan campaigns. This threat actor has been operational since 2018, primarily targeting financial institutions, retail sectors, and other industries with high monetary value. The group's primary modus operandi involves phishing emails, credential theft, and unauthorized wire transfers. TA570 has demonstrated a high level of technical expertise, leveraging Qbot's capabilities to deploy malicious payloads, bypass security measures, and execute large-scale financial fraud. The actor's activities have been observed globally, with a particular focus on North America, Europe, and Asia Pac regions.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA570 has been involved in multiple campaigns targeting financial institutions, using phishing as the primary entry vector. The group's operational tempo is high, with frequent campaigns often synchronized with global business hours. Notable past operations include large-scale wire fraud attempts and BEC attacks targeting corporate accounts. TA570 frequently adapts its tactics to evade detection, including updating Qbot's configurations and leveraging new domains for C2 communication.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information available on TA570 is sufficient to provide a detailed analysis of its operations and capabilities. However, some specifics about the group's exact campaigns, TTPs beyond Qbot-related activity, and precise targeting criteria remain inferred or less clear. Additional data from recent campaigns could further refine this intelligence.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics