← threatfilter.dev / all groups / TA551
TA551
Also known as: GOLD CABIN · Shathak
Overview
TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns.
Capabilities
- Custom malware/implant development — ATT&CK: 4 attributed custom malware families
TTPs — 14 techniques across 5 tactics
Reconnaissance
-
T1589.002Email Addresses
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1059.003Windows Command Shell -
T1204.002Malicious File
Stealth
-
T1027.003Steganography -
T1027.010Command Obfuscation -
T1036Masquerading -
T1218.005Mshta -
T1218.010Regsvr32 -
T1218.011Rundll32
Command and Control
-
T1071.001Web Protocols -
T1105Ingress Tool Transfer -
T1132.001Standard Encoding -
T1568.002Domain Generation Algorithms
Tools & malware (5)
QakBot · IcedID · Valak · Sliver · Ursnif