← threatfilter.dev / all groups / TA505
TA505
Also known as: Hive0065 · Spandex Tempest · CHIMBORAZO
Overview
TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.
Targets
Education · Finance · Healthcare · Hospitality · Retail
Regions
Australia · Canada · Czech Republic · Germany · Hungary · India · Japan · Romania · Serbia · Singapore · South Korea · Spain · Thailand · Turkey · United Kingdom · United States
Capabilities
- Custom malware/implant development — ATT&CK: 11 attributed custom malware families
TTPs — 34 techniques across 9 tactics
Resource Development
-
T1583.001Domains -
T1588.001Malware -
T1588.002Tool -
T1608.001Upload Malware
Initial Access
-
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1059.007JavaScript -
T1106Native API -
T1204.001Malicious Link -
T1204.002Malicious File -
T1559.002Dynamic Data Exchange
Stealth
-
T1027.002Software Packing -
T1027.010Command Obfuscation -
T1027.013Encrypted/Encoded File -
T1055.001Dynamic-link Library Injection -
T1078.002Domain Accounts -
T1140Deobfuscate/Decode Files or Information -
T1218.007Msiexec -
T1218.011Rundll32
Defense Impairment
-
T1112Modify Registry -
T1553.002Code Signing -
T1553.005Mark-of-the-Web Bypass -
T1685Disable or Modify Tools
Credential Access
-
T1552.001Credentials In Files -
T1555.003Credentials from Web Browsers
Discovery
-
T1069Permission Groups Discovery -
T1087.003Email Account
Command and Control
-
T1071.001Web Protocols -
T1105Ingress Tool Transfer -
T1568.001Fast Flux DNS
Impact
Tools & malware (16)
AdFind · Clop · Azorult · FlawedAmmyy · Mimikatz · Dridex · TrickBot · Get2 · FlawedGrace · Cobalt Strike · ServHelper · BloodHound · Amadey · SDBbot · Net · PowerSploit
Reporting (3)
- How Microsoft names threat actors — Microsoft
- TA505: A Brief History of Their Time — Terefos, A
- TA505 Continues to Infect Networks With SDBbot RAT — Frydrych, M