TA551
Also known as: GOLD CABIN · Shathak
Overview
TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns.
Naming & attribution
TA551 is tracked under 3 names across the industry. It uses 14 documented ATT&CK techniques — more than 40% of the 174 groups tracked here. Activity attributed since at least 2018.
| Name | First reported by |
|---|---|
| GOLD CABIN | Secureworks |
| Shathak | Duncan, B |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1568.002Domain Generation Algorithms — used by 2 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- LazyScripter — 8 shared techniques (31% overlap)
- Nomadic Octopus Russia — 5 shared techniques (31% overlap)
- Rancor — 5 shared techniques (28% overlap)
- APT19 China — 7 shared techniques (25% overlap)
- WIRTE — 7 shared techniques (21% overlap)
- PLATINUM — 4 shared techniques (19% overlap)
Malware families with current indicators
4 families attributed to TA551, carrying 1,965 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Sliver 1,562 indicators
- QakBot 360 indicators
- Valak 37 indicators
- IcedId 6 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Custom malware/implant development — ATT&CK: 4 attributed custom malware families
TTPs — 14 techniques across 5 tactics
Reconnaissance
-
T1589.002Email Addresses
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1059.003Windows Command Shell -
T1204.002Malicious File
Stealth
-
T1027.003Steganography -
T1027.010Command Obfuscation -
T1036Masquerading -
T1218.005Mshta -
T1218.010Regsvr32 -
T1218.011Rundll32
Command and Control
-
T1071.001Web Protocols -
T1105Ingress Tool Transfer -
T1132.001Standard Encoding -
T1568.002Domain Generation Algorithms
Tools & malware (5)
QakBot · IcedID · Valak · Sliver · Ursnif