TA575 is a cybercriminal group known for distributing Dridex malware targeting the financial sector.
Analyst brief
TA575 is a cybercriminal group active since at least late 2020, operating as an affiliate for distributing Dridex malware. They primarily target the financial sector and other organizations, disseminating malware such as Dridex, Qakbot, and WastedLocker. Their main TTPs involve large-scale phishing campaigns using malicious URLs, Office attachments, and password-protected files. Defenders should focus on scrutinizing suspicious email attachments, especially password-protected documents, and enhance network monitoring for Dridex/Qakbot loader activity.
TA575
unknown
TA575 is a Dridex affiliate tracked by Proofpoint since late 2020. This group distributes malware such as Dridex, Qakbot, and WastedLocker via malicious URLs, Office attachments, and password-protected files. On average, TA575 distributes almost 4,000 messages per campaign impacting hundreds of organizations.