TA577

G1037

Threat group.View on attack.mitre.org

About this group

TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in 2023.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027.009
Embedded Payloads

TA577 has used LNK files to execute embedded DLLs.

T1059.003
Windows Command Shell

TA577 has used BAT files in malware execution chains.

T1059.007
JavaScript

TA577 has used JavaScript to execute additional malicious payloads.

T1204.001
Malicious Link

TA577 has lured users into executing malicious JavaScript files by sending malicious links via email.

T1566.002
Spearphishing Link

TA577 has sent emails containing links to malicious JavaScript files.

T1586.002
Email Accounts

TA577 has sent thread hijacked messages from compromised emails.

Software3

Campaigns0

None recorded.

References1

  1. Latrodectus APR 2024 Open source
    Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.