Threat group.View on attack.mitre.org
TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns.
| Technique | Procedure example |
|---|---|
| T1027.003 Steganography |
TA551 has hidden encoded data for malware DLLs in a PNG. |
| T1027.010 Command Obfuscation |
TA551 has used obfuscated variable names in a JavaScript configuration file. |
| T1036 Masquerading |
TA551 has masked malware DLLs as dat and jpg files. |
| T1059.003 Windows Command Shell |
TA551 has used |
| T1071.001 Web Protocols |
TA551 has used HTTP for C2 communications. |
| T1105 Ingress Tool Transfer |
TA551 has retrieved DLLs and installer binaries for malware execution from C2. |
| T1132.001 Standard Encoding |
TA551 has used encoded ASCII text for initial C2 communications. |
| T1204.002 Malicious File |
TA551 has prompted users to enable macros within spearphishing attachments to install malware. |
| T1218.005 Mshta |
TA551 has used mshta.exe to execute malicious payloads. |
| T1218.010 Regsvr32 |
TA551 has used regsvr32.exe to load malicious DLLs. |
| T1218.011 Rundll32 |
TA551 has used rundll32.exe to load malicious DLLs. |
| T1566.001 Spearphishing Attachment |
TA551 has sent spearphishing attachments with password protected ZIP files. |
| T1568.002 Domain Generation Algorithms |
TA551 has used a DGA to generate URLs from executed macros. |
| T1589.002 Email Addresses |
TA551 has used spoofed company emails that were acquired from email clients on previously infected hosts to target other individuals. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.