TA578

G1038

Threat group.View on attack.mitre.org

About this group

TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1059.007
JavaScript

TA578 has used JavaScript files in malware execution chains.

T1204.001
Malicious Link

TA578 has placed malicious links in contact forms on victim sites, often spoofing a copyright complaint, to redirect users to malicious file downloads.

T1583.006
Web Services

TA578 has used Google Firebase to host malicious scripts.

T1594
Search Victim-Owned Websites

TA578 has filled out contact forms on victims' websites to direct them to adversary-controlled URLs.

Software3

Campaigns0

None recorded.

References2

  1. Bitsight Latrodectus June 2024 Open source
    Batista, J. (2024, June 17). Latrodectus, are you coming back?. Retrieved September 13, 2024.
  2. Latrodectus APR 2024 Open source
    Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.