TA547 is a financially motivated cybercriminal actor distributing banking trojans since at least 2017.
Analyst brief
TA547 is a financially motivated cybercriminal actor active since at least November 2017. It primarily targets users and organizations in countries such as Australia, Germany, the United Kingdom, and Italy. This threat actor distributes a wide range of banking trojans including ZLoader, Gootkit, Ursnif, Corebot, Panda Banker, Atmos, and Mazar Bot, likely through phishing campaigns and social engineering. Defenders should urgently strengthen email security filters, conduct user awareness training to spot social engineering attempts, and enable endpoint monitoring for known Indicators of Compromise (IoCs) associated with the listed malware families.
TA547
unknown
TA547 is responsible for many other campaigns since at least November 2017. The other campaigns by the actor were often localized to countries such as Australia, Germany, the United Kingdom, and Italy. Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.