TA555 is a threat group active since 2018, targeting hospitality and telecom sectors with the AdvisorsBot downloader.
Analyst brief
TA555 is a threat actor observed since May 2018, primarily targeting the hospitality (hotels, restaurants) and telecommunications sectors through malicious email campaigns distributing a downloader called AdvisorsBot. Initial TTPs involve using AdvisorsBot as a first-stage payload that loads a fingerprinting module to identify high-value targets for further infection with additional payloads, with the malware actively rewritten in PowerShell and .NET. Defenders should focus on scrutinizing email attachments, monitoring for suspicious PowerShell and .NET execution chains indicative of the fingerprinting activity, and investigating any signs of follow-on payloads after initial compromise.
TA555
unknown
Beginning in May 2018, Proofpoint researchers observed a previously undocumented downloader dubbed AdvisorsBot appearing in malicious email campaigns. The campaigns appear to primarily target hotels, restaurants, and telecommunications, and are distributed by an actor we track as TA555. To date, we have observed AdvisorsBot used as a first-stage payload, loading a fingerprinting module that, as with Marap, is presumably used to identify targets of interest to further infect with additional modules or payloads. AdvisorsBot is under active development and we have also observed another version of the malware completely rewritten in PowerShell and .NET.