NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / TA551

TA551

Also known as: GOLD CABIN · Shathak

Overview

TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns.

Capabilities

  • Custom malware/implant development — ATT&CK: 4 attributed custom malware families

TTPs — 14 techniques across 5 tactics

Reconnaissance

Initial Access

Execution

Stealth

Command and Control

Tools & malware (5)

QakBot · IcedID · Valak · Sliver · Ursnif

Reporting (2)