Threat group.View on attack.mitre.org
TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in 2023.
| Technique | Procedure example |
|---|---|
| T1027.009 Embedded Payloads |
TA577 has used LNK files to execute embedded DLLs. |
| T1059.003 Windows Command Shell |
TA577 has used BAT files in malware execution chains. |
| T1059.007 JavaScript |
TA577 has used JavaScript to execute additional malicious payloads. |
| T1204.001 Malicious Link |
TA577 has lured users into executing malicious JavaScript files by sending malicious links via email. |
| T1566.002 Spearphishing Link |
TA577 has sent emails containing links to malicious JavaScript files. |
| T1586.002 Email Accounts |
TA577 has sent thread hijacked messages from compromised emails. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.