Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: DEV-0450

Description

One of the most active Qbot malware affiliates, Proofpoint has tracked the large cybercrime threat actor TA570 since 2018.

AI Analysis

· 2 weeks ago

Executive Summary

TA570, also known as DEV-0450, is a prominent cybercrime threat actor associated with the Qbot malware family. Active since at least 2018, TA570 has been linked to several high-profile campaigns targeting financial institutions and other industries. The group primarily relies on banking Trojans and phishing activities to achieve its objectives, making it a significant threat to global enterprises.

Goals & Targeting

TA570's strategic objectives appear to be primarily financially motivated, focusing on extracting sensitive information such as banking credentials and facilitating unauthorized transactions. The group's targeting profile includes financial institutions, retail sectors, and other organizations with accessible financial systems. TA570 often uses phishing campaigns and malware distribution to gain initial access to victim networks, enabling subsequent lateral movement and data exfiltration.

Enhanced Description

TA570 is one of the most active affiliates in the Qbot malware ecosystem, known for its sophisticated banking Trojan campaigns. This threat actor has been operational since 2018, primarily targeting financial institutions, retail sectors, and other industries with high monetary value. The group's primary modus operandi involves phishing emails, credential theft, and unauthorized wire transfers. TA570 has demonstrated a high level of technical expertise, leveraging Qbot's capabilities to deploy malicious payloads, bypass security measures, and execute large-scale financial fraud. The actor's activities have been observed globally, with a particular focus on North America, Europe, and Asia Pac regions.

Key Capabilities

  • Qbot malware deployment for credential theft
  • Phishing campaigns leveraging email as an infection vector
  • Banking Trojan activities targeting financial institutions
  • Unauthorised wire transfers and BEC (Business Email Compromise) techniques
  • SMB protocol abuse for lateral movement
  • RDP brute force attacks for initial access
  • C2 communication via HTTP/HTTPS proxies

MITRE ATT&CK Tactics

Credential Access
Persistence
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1003.001 - OS Credential Dumping: Windows Credential Editor
T1566.001 - Phishing Emails with Malicious Links
T1184 - Remote File Hash Calculation
T1078 - Internal Domain Communication
T1021 - SMB Client Abuse
T1070 - Application Layer Protocol隧道
T1070.001 - RDP Access

Software / Tooling

Qbot
Cobalt Strike
Phishing Email Tools
RDP Brute Force Tools

Campaigns & Victims

TA570 has been involved in multiple campaigns targeting financial institutions, using phishing as the primary entry vector. The group's operational tempo is high, with frequent campaigns often synchronized with global business hours. Notable past operations include large-scale wire fraud attempts and BEC attacks targeting corporate accounts. TA570 frequently adapts its tactics to evade detection, including updating Qbot's configurations and leveraging new domains for C2 communication.

IOC Patterns

  • Qbot malware instances targeting Windows systems
  • Phishing emails with malicious links or attachments mimicking financial institutions
  • C2 communications over legitimate-looking domains (e.g., banking.mailservice.com)
  • SMB protocol traffic between compromised machines
  • RDP brute force activity from known TA570 IP addresses

Recommended Actions

  • Implement network monitoring for Qbot-related IOC patterns and SMB/RDP traffic anomalies.
  • Regularly patch and update software to mitigate known vulnerabilities exploited by Qbot.
  • Enforce multi-factor authentication (MFA) for financial transactions and critical systems.
  • Educate employees on identifying phishing emails and suspicious communication.
  • Deploy endpoint detection and response (EDR) solutions to detect and block Qbot payloads.
  • Monitor for unauthorized wire transfers and implement additional layers of verification.
  • Review and secure RDP access, disabling it where unnecessary.

Suggested Tags

APT
Financial Fraud
Banking Trojan
Phishing
Qbot

Confidence Assessment

The information available on TA570 is sufficient to provide a detailed analysis of its operations and capabilities. However, some specifics about the group's exact campaigns, TTPs beyond Qbot-related activity, and precise targeting criteria remain inferred or less clear. Additional data from recent campaigns could further refine this intelligence.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
APT
Financial Fraud
Banking Trojan
Phishing
Qbot

Details

Type
Unknown
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.