TA570
One of the most active Qbot malware affiliates, Proofpoint has tracked the large cybercrime threat actor TA570 since 2018.
TA570 (DEV-0450) is an active Qbot malware affiliate tracked since 2018.
TA570 (DEV-0450) is one of the most active Qbot malware affiliates, tracked by Proofpoint since 2018. This group targets organizations. Their characteristic TTPs include Qbot loader delivery via phishing email campaigns, thread hijacking, and leveraging existing email chains. Defenders should be vigilant for suspicious email attachments, especially unusual document macros leading to Qbot distribution.
One of the most active Qbot malware affiliates, Proofpoint has tracked the large cybercrime threat actor TA570 since 2018.
TA570 primarily uses tactics such as thread hijacking, leveraging existing email chains, and phishing email campaigns to deliver the Qbot loader.
Defenders should be vigilant for suspicious email attachments, especially unusual document macros leading to the distribution of Qbot.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.