TA505

G0092

Threat group.View on attack.mitre.org

About this group

TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.

Techniques used34

Procedure examples34

TechniqueProcedure example
T1027.002
Software Packing

TA505 has used UPX to obscure malicious code.

T1027.010
Command Obfuscation

TA505 has used base64 encoded PowerShell commands.

T1027.013
Encrypted/Encoded File

TA505 has password-protected malicious Word documents.

T1055.001
Dynamic-link Library Injection

TA505 has been seen injecting a DLL into winword.exe.

T1059.001
PowerShell

TA505 has used PowerShell to download and execute malware and reconnaissance scripts.

T1059.003
Windows Command Shell

TA505 has executed commands using cmd.exe.

T1059.005
Visual Basic

TA505 has used VBS for code execution.

T1059.007
JavaScript

TA505 has used JavaScript for code execution.

T1069
Permission Groups Discovery

TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run net group /domain.

T1071.001
Web Protocols

TA505 has used HTTP to communicate with C2 nodes.

T1078.002
Domain Accounts

TA505 has used stolen domain admin accounts to compromise additional hosts.

T1087.003
Email Account

TA505 has used the tool EmailStealer to steal and send lists of e-mail addresses to a remote server.

T1105
Ingress Tool Transfer

TA505 has downloaded additional malware to execute on victim systems.

T1106
Native API

TA505 has deployed payloads that use Windows API calls on a compromised host.

T1112
Modify Registry

TA505 has used malware to disable Windows Defender through modification of the Registry.

View all 34 procedure examples

Software16

Campaigns0

None recorded.

References5

  1. Korean FSI TA505 2020 Open source
    Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.
  2. NCC Group TA505 Open source
    Terefos, A. (2020, November 18). TA505: A Brief History of Their Time. Retrieved July 14, 2022.
  3. Proofpoint TA505 Jan 2019 Open source
    Schwarz, D. and Proofpoint Staff. (2019, January 9). ServHelper and FlawedGrace - New malware introduced by TA505. Retrieved May 28, 2019.
  4. Proofpoint TA505 June 2018 Open source
    Proofpoint Staff. (2018, June 8). TA505 shifts with the times. Retrieved May 28, 2019.
  5. Proofpoint TA505 Sep 2017 Open source
    Proofpoint Staff. (2017, September 27). Threat Actor Profile: TA505, From Dridex to GlobeImposter. Retrieved May 28, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.