TA578
TA578 is a financially motivated threat actor tracked by Proofpoint since May 2020. It is associated with email- and web-based initial access activity and has delivered multiple malware families over time, including Ursnif, IcedID, KPOT Stealer, Buer Loader, BazaLoader, Bumblebee, Cobalt Strike, and more recently Latrodectus. Proofpoint reported TA578 delivering IcedID since June 2020 and noted recurring use of "stolen images" / copyright-violation themes. The actor has also been described in reporting as associated with botnet-based operations involving SSLoad and Bumblebee malware. TA578 commonly uses social-engineering lures and delivery chains centered on malicious links and scripts. Reported tradecraft includes abuse of website contact forms to initiate conversations with targets, often impersonating companies and sending legal threats about alleged copyright infringement. TA578 has placed malicious links in contact forms on victim sites to redirect users to malware downloads. In observed campaigns, victims were redirected to personalized landing pages that downloaded JavaScript from Google Firebase; the JavaScript then invoked MSIEXEC to run an MSI from a WebDAV share, which executed a bundled DLL to launch Latrodectus. TA578 has also used JavaScript files in malware execution chains and has hosted malicious scripts on Google Firebase. Since mid-January 2024, Latrodectus has been almost exclusively distributed by TA578 in observed campaigns. Proofpoint observed TA578 delivering Latrodectus via a DanaBot infection in December 2023, and later via contact-form and copyright-themed lures in February 2024. Reporting describes TA578 as one of the initial access brokers associated with Latrodectus campaigns. No additional aliases or sub-groups for TA578 are directly supported in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
Observables
79 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the MMC/GrimResource detection analytic.
Listed in annotations as a threat actor associated with the detection context; no specific activity beyond inclusion in the analytic metadata is described.
Listed as a threat actor associated with malicious link execution and spearphishing attachment activity relevant to ISO/LNK delivery detection.
Uses Latrodectus in phishing campaigns.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.