TA505
Also known as: Hive0065 · Spandex Tempest · CHIMBORAZO
Overview
TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.
Naming & attribution
TA505 is tracked under 4 names across the industry. It uses 34 documented ATT&CK techniques — more than 70% of the 174 groups tracked here. Activity attributed since at least 2014.
| Name | First reported by |
|---|---|
| Hive0065 | Frydrych, M |
| Spandex Tempest | Microsoft |
| CHIMBORAZO | Microsoft |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1553.005Mark-of-the-Web Bypass — used by 3 of 174 groups -
T1568.001Fast Flux DNS — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- LazyScripter — 14 shared techniques (35% overlap)
- WIRTE — 15 shared techniques (33% overlap)
- Molerats — 12 shared techniques (32% overlap)
- Saint Bear Russia — 12 shared techniques (30% overlap)
- TA2541 — 14 shared techniques (29% overlap)
- Gorgon Group Pakistan — 11 shared techniques (28% overlap)
Malware families with current indicators
8 families attributed to TA505, carrying 1,675 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Dridex 987 indicators
- Amadey 373 indicators
- AZORult 269 indicators
- FlawedAmmyy 21 indicators
- Get2 10 indicators
- Clop 8 indicators
- Trickbot 4 indicators
- SDBBot 2 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Targets
Education · Finance · Healthcare · Hospitality · Retail
Regions
Australia · Canada · Czech Republic · Germany · Hungary · India · Japan · Romania · Serbia · Singapore · South Korea · Spain · Thailand · Turkey · United Kingdom · United States
Capabilities
- Custom malware/implant development — ATT&CK: 11 attributed custom malware families
TTPs — 34 techniques across 9 tactics
Resource Development
-
T1583.001Domains -
T1588.001Malware -
T1588.002Tool -
T1608.001Upload Malware
Initial Access
-
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1059.007JavaScript -
T1106Native API -
T1204.001Malicious Link -
T1204.002Malicious File -
T1559.002Dynamic Data Exchange
Stealth
-
T1027.002Software Packing -
T1027.010Command Obfuscation -
T1027.013Encrypted/Encoded File -
T1055.001Dynamic-link Library Injection -
T1078.002Domain Accounts -
T1140Deobfuscate/Decode Files or Information -
T1218.007Msiexec -
T1218.011Rundll32
Defense Impairment
-
T1112Modify Registry -
T1553.002Code Signing -
T1553.005Mark-of-the-Web Bypass -
T1685Disable or Modify Tools
Credential Access
-
T1552.001Credentials In Files -
T1555.003Credentials from Web Browsers
Discovery
-
T1069Permission Groups Discovery -
T1087.003Email Account
Command and Control
-
T1071.001Web Protocols -
T1105Ingress Tool Transfer -
T1568.001Fast Flux DNS
Impact
Tools & malware (16)
AdFind · Clop · Azorult · FlawedAmmyy · Mimikatz · Dridex · TrickBot · Get2 · FlawedGrace · Cobalt Strike · ServHelper · BloodHound · Amadey · SDBbot · Net · PowerSploit
Reporting (3)
- How Microsoft names threat actors — Microsoft
- TA505: A Brief History of Their Time — Terefos, A
- TA505 Continues to Infect Networks With SDBbot RAT — Frydrych, M