TA577
Overview
TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in 2023.
Naming & attribution
TA577 is tracked under 1 names across the industry. It uses 6 documented ATT&CK techniques — more than 17% of the 174 groups tracked here.
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1027.009Embedded Payloads — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Evilnum — 3 shared techniques (21% overlap)
- Machete — 3 shared techniques (21% overlap)
- LazyScripter — 4 shared techniques (18% overlap)
- Molerats — 3 shared techniques (16% overlap)
- WIRTE — 4 shared techniques (14% overlap)
- Saint Bear Russia — 3 shared techniques (14% overlap)
Malware families with current indicators
3 families attributed to TA577, carrying 944 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- QakBot 360 indicators
- Latrodectus 334 indicators
- Pikabot 250 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 6 techniques across 4 tactics
Resource Development
-
T1586.002Email Accounts
Initial Access
-
T1566.002Spearphishing Link
Execution
-
T1059.003Windows Command Shell -
T1059.007JavaScript -
T1204.001Malicious Link
Stealth
-
T1027.009Embedded Payloads
Tools & malware (3)
Pikabot · QakBot · Latrodectus
Reporting (1)
- Latrodectus: This Spider Bytes Like Ice — Proofpoint Threat Research and Team Cymru S2 Threat Research