TA516 is a financially motivated threat actor distributing banking Trojans and cryptocurrency coinminers via SmokeLoader.
Analyst brief
TA516 is an uncategorized threat actor active since mid-2017, known for distributing malware primarily through the SmokeLoader downloader. They target victims with financially motivated payloads, often deploying banking Trojans like Panda Banker alongside cryptocurrency coinminers in the same campaigns. Their key TTPs include macro-laden fake resume documents that execute PowerShell download scripts, as well as malicious JavaScript files hosted on Google Drive to fetch SmokeLoader. Defenders should focus on blocking macro execution in suspicious email attachments, monitoring PowerShell download chains, and detecting network connections associated with SmokeLoader's C2 infrastructure.
TA516
unknown
This actor typically distributes instances of the SmokeLoader intermediate downloader, which, in turn, downloads additional malware of the actor’s choice -- often banking Trojans. Figure 3 shows a lure document from a November campaign in which TA516 distributed fake resumes with malicious macros that, if enabled, launch a PowerShell script that downloads SmokeLoader. In this instance, we observed SmokeLoader downloading a Monero coinminer. Since the middle of 2017, TA516 has used similar macro-laden documents as well as malicious JavaScript hosted on Google Drive to distribute both Panda Banker and a coinminer executable via SmokeLoader, often in the same campaigns.