TA578
TA578, a threat actor that Proofpoint researchers have been tracking since May of 2020. TA578 has previously been observed in email-based campaigns delivering Ursnif, IcedID, KPOT Stealer, Buer Loader, BazaLoader, and Cobalt Strike.
TA578 is a financially motivated threat actor distributing Bumblebee, Latrodectus, and IcedID loaders via email campaigns.
TA578 is a threat actor active since at least May 2020, primarily conducting email-based campaigns. Believed to be financially motivated, this actor delivers payloads such as Bumblebee, Latrodectus, and IcedID loaders to its victims. Their TTPs include searching victim-owned websites for reconnaissance, abusing Web Services for resource development, and using JavaScript and malicious links for execution. Defenders should strengthen email security gateways, train users to identify suspicious links, and actively monitor for IOCs associated with the 'Bumblebee', 'Latrodectus', and 'IcedID' malware.
TA578, a threat actor that Proofpoint researchers have been tracking since May of 2020. TA578 has previously been observed in email-based campaigns delivering Ursnif, IcedID, KPOT Stealer, Buer Loader, BazaLoader, and Cobalt Strike.
Monitor web traffic to detect suspicious search activities.
Monitor to identify and disrupt suspicious web services infrastructure.
Monitor environments to detect and prevent unauthorized JavaScript execution.
Monitor user activity to identify and block access to malicious links.
TA578 delivers loaders such as Bumblebee, Latrodectus, and IcedID to its victims.
TA578's TTPs include searching victim-owned websites for reconnaissance, abusing Web Services for resource development, and using JavaScript and malicious links for execution.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.