TA578
Overview
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.
Naming & attribution
TA578 is tracked under 1 names across the industry. It uses 4 documented ATT&CK techniques — more than 9% of the 174 groups tracked here.
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Saint Bear Russia — 3 shared techniques (16% overlap)
- LazyScripter — 3 shared techniques (14% overlap)
- APT-C-36 — 3 shared techniques (8% overlap)
- Earth Lusca China — 3 shared techniques (7% overlap)
- Contagious Interview North Korea — 3 shared techniques (5% overlap)
- APT32 Vietnam — 3 shared techniques (4% overlap)
Malware families with current indicators
3 families attributed to TA578, carrying 913 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- BumbleBee 573 indicators
- Latrodectus 334 indicators
- IcedId 6 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 4 techniques across 3 tactics
Reconnaissance
Resource Development
-
T1583.006Web Services
Execution
-
T1059.007JavaScript -
T1204.001Malicious Link
Tools & malware (3)
Bumblebee · Latrodectus · IcedID
Reporting (2)
- Latrodectus, are you coming back? — Batista, J
- Latrodectus: This Spider Bytes Like Ice — Proofpoint Threat Research and Team Cymru S2 Threat Research