NEW: Group Profiler — instant APT intel lookup. Try it →

TA577

Overview

TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in 2023.

Naming & attribution

TA577 is tracked under 1 names across the industry. It uses 6 documented ATT&CK techniques — more than 17% of the 174 groups tracked here.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1027.009 Embedded Payloads — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Evilnum — 3 shared techniques (21% overlap)
  • Machete — 3 shared techniques (21% overlap)
  • LazyScripter — 4 shared techniques (18% overlap)
  • Molerats — 3 shared techniques (16% overlap)
  • WIRTE — 4 shared techniques (14% overlap)
  • Saint Bear Russia — 3 shared techniques (14% overlap)

Malware families with current indicators

3 families attributed to TA577, carrying 944 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • QakBot 360 indicators
  • Latrodectus 334 indicators
  • Pikabot 250 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Custom malware/implant development — ATT&CK: 3 attributed custom malware families

TTPs — 6 techniques across 4 tactics

Resource Development

Initial Access

Execution

Stealth

Tools & malware (3)

Pikabot · QakBot · Latrodectus

Reporting (1)