← threatfilter.dev / all groups / TA578
TA578
Overview
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.
Capabilities
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 4 techniques across 3 tactics
Reconnaissance
Resource Development
-
T1583.006Web Services
Execution
-
T1059.007JavaScript -
T1204.001Malicious Link
Tools & malware (3)
Bumblebee · Latrodectus · IcedID
Reporting (2)
- Latrodectus, are you coming back? — Batista, J
- Latrodectus: This Spider Bytes Like Ice — Proofpoint Threat Research and Team Cymru S2 Threat Research