TA505 (SectorJ04) is a financially motivated cybercrime group known for Dridex banking trojan and Locky ransomware.
Analyst brief
TA505 (a.k.a. SectorJ04, GOLD TAHOE) is a financially motivated cybercrime group known for operating Dridex banking trojan and Locky ransomware. This actor targets the finance, education, healthcare, retail, and hospitality sectors globally. They utilize spearphishing attachments for initial access, deploy tools like Cobalt Strike and TrickBot, and deliver Clop ransomware while using Fast Flux DNS for C2 resilience. Defenders should focus on email security, monitor for Msiexec abuse, and investigate suspicious domain resolution patterns.
TA505
SectorJ04SectorJ04 GroupGRACEFUL SPIDER
unknown
TA505, the name given by Proofpoint, has been in the cybercrime business for at least four years. This is the group behind the infamous Dridex banking trojan and Locky ransomware, delivered through malicious email campaigns via Necurs botnet. Other malware associated with TA505 include Philadelphia and GlobeImposter ransomware families.