TA8888 is a cybercriminal group known for distributing TrickBot and BazaLoader through highly personalized phishing campaigns.
Analyst brief
TA800 operates as a distributor for TrickBot and BazaLoader, targeting a broad range of industries across North America with banking Trojans and malware loaders. They use highly personalized phishing emails containing employee names, job titles, and company branding, with lures related to payments, meetings, terminations, bonuses, and complaints. Defenders should scrutinize emails that include internal HR and financial themes with personalized details, and monitor for suspicious processes spawned by document lures that may lead to BazaLoader or TrickBot C2 traffic.
TA800
unknown
This attacker is an affiliate distributor of the The Trick, also known as Trickbot, and BazaLoader. (For more on how affiliates work, see the description of TA573).
TA800 has targeted a wide range of industries in North America, infecting victims with banking Trojans and malware loaders (malware designed to download other malware onto a compromised device). Malicious emails have often included recipients’ names, titles and employers along with phishing pages designed to look like the targeted company. Lures have included hard-to-resist subjects such as related to payment, meetings, termination, bonuses and complaints in the subject line or body of the email.
What types of malware does the TA800 group distribute?+
TA800 operates as a distributor for TrickBot and BazaLoader, infecting victims with banking Trojans and malware loaders.
What personalization tactics does TA800 use in phishing emails to gain initial access?+
TA800 uses highly personalized phishing emails containing employee names, job titles, and company branding, with lures related to payments, meetings, bonuses, and complaints.