TA516TA516

Also known as: TA516

Known aliases
1

Profile

This actor typically distributes instances of the SmokeLoader intermediate downloader, which, in turn, downloads additional malware of the actor’s choice -- often banking Trojans. Figure 3 shows a lure document from a November campaign in which TA516 distributed fake resumes with malicious macros that, if enabled, launch a PowerShell script that downloads SmokeLoader. In this instance, we observed SmokeLoader downloading a Monero coinminer. Since the middle of 2017, TA516 has used similar macro-laden documents as well as malicious JavaScript hosted on Google Drive to distribute both Panda Banker and a coinminer executable via SmokeLoader, often in the same campaigns.

Aliases· 1

TA516

Compliance frameworks testing this (incoming)1

TypeTargetConfidenceTier
ComplianceControlai_act-art9100%live

References

  1. https://www.thaicert.or.th/downloads/files/Threat_Group_Cards_v2.0.pdf

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
TA554
Actor
TA406
Actor
TA571
Actor
TA577
Actor
TA547
Actor
TA579
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.