TA505

EvilCorp · ATK 103 · SectorJ04 · Hive0065 · GRACEFUL SPIDER · GOLD TAHOE · Dudear · CHIMBORAZO

  • CA
    Canada
  • CN
    China
  • FR
    France
  • DE
    Germany
  • HU
    Hungary
  • IN
    India
  • IT
    Italy
  • MW
    Malawi
  • MX
    Mexico
  • PK
    Pakistan
  • KR
    South Korea
  • TW
    Taiwan
  • UA
    Ukraine
  • GB
    United Kingdom
  • US
    United States of America

General description

The activity of the TA505 group was first discovered and described in 2014, but the group itself is believed to have been around since 2006. The group's victims feature companies from various sectors around the world. The group employs a wide range of tools, designed to handle any task. Phishing is the main means applied to penetrate an infrastructure. It finds its victims all over the world, avoiding the CIS. According to researchers, the group is presumed to be Russian-speaking. TA505 follows the latest trends, using the COVID-19 theme and ZeroLogon vulnerability in its attacks.

Objectives

  • Cash theft

Tools

  • Dridex
  • Shifu
  • Trickbot
  • Zeus
  • FlawedAmmyy
  • FlawedGrace
  • SDBbot
  • BackNet
  • RMS
  • Neutrino
  • Amadey
  • GameOver Zeus
  • ServHelper
  • FlowerPippi
  • Locky
  • Jaff
  • GlobeImposter
  • Rapid
  • Clop/CryptoMix
  • MINERBRIDE
  • Bart
  • DoppelPaymer
  • Philadelphia
  • Snatch
  • DEWMODE
  • GraceWire
  • Kegotip
  • EmailStealer
  • Pony
  • Metasploit
  • Cobalt Strike
  • AndroMut
  • Rockloader
  • Gelup
  • Get2
  • Quant
  • Marap
  • TinyMet

Targeted countries

  • CA
    Canada
  • CN
    China
  • FR
    France
  • DE
    Germany
  • HU
    Hungary
  • IN
    India
  • IT
    Italy
  • MW
    Malawi
  • MX
    Mexico
  • PK
    Pakistan
  • KR
    South Korea
  • TW
    Taiwan
  • UA
    Ukraine
  • GB
    United Kingdom
  • US
    United States of America

Alternative names

  • EvilCorp
  • ATK 103
  • SectorJ04
  • Hive0065
  • GRACEFUL SPIDER
  • GOLD TAHOE
  • Dudear
  • CHIMBORAZO
Targeted sectors:
  • The finance sector
  • The energy sector
  • Pharmaceuticals
  • Aerospace industry
  • State sector
  • Research companies

Target countries

Reports by Positive Technologies and other researchers

MITRE ATT&CK techniques, used by the group