NEW: Group Profiler — instant APT intel lookup. Try it →

TA551

Also known as: GOLD CABIN · Shathak

Overview

TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns.

Naming & attribution

TA551 is tracked under 3 names across the industry. It uses 14 documented ATT&CK techniques — more than 40% of the 174 groups tracked here. Activity attributed since at least 2018.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
GOLD CABINSecureworks
ShathakDuncan, B

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1568.002 Domain Generation Algorithms — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • LazyScripter — 8 shared techniques (31% overlap)
  • Nomadic Octopus Russia — 5 shared techniques (31% overlap)
  • Rancor — 5 shared techniques (28% overlap)
  • APT19 China — 7 shared techniques (25% overlap)
  • WIRTE — 7 shared techniques (21% overlap)
  • PLATINUM — 4 shared techniques (19% overlap)

Malware families with current indicators

4 families attributed to TA551, carrying 1,965 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Sliver 1,562 indicators
  • QakBot 360 indicators
  • Valak 37 indicators
  • IcedId 6 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Custom malware/implant development — ATT&CK: 4 attributed custom malware families

TTPs — 14 techniques across 5 tactics

Reconnaissance

Initial Access

Execution

Stealth

Command and Control

Tools & malware (5)

QakBot · IcedID · Valak · Sliver · Ursnif

Reporting (2)