Threat group.View on attack.mitre.org
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.
| Technique | Procedure example |
|---|---|
| T1059.007 JavaScript |
TA578 has used JavaScript files in malware execution chains. |
| T1204.001 Malicious Link |
TA578 has placed malicious links in contact forms on victim sites, often spoofing a copyright complaint, to redirect users to malicious file downloads. |
| T1583.006 Web Services |
TA578 has used Google Firebase to host malicious scripts. |
| T1594 Search Victim-Owned Websites |
TA578 has filled out contact forms on victims' websites to direct them to adversary-controlled URLs. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.