RU

TA570TA570

Also known as: DEV-0450 · TA570

Origin
RU
Known aliases
2

Profile

TA570 is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as DEV-0450. Original record: One of the most active Qbot malware affiliates, Proofpoint has tracked the large cybercrime threat actor TA570 since 2018.

Aliases· 2

DEV-0450TA570

Compliance frameworks testing this (incoming)8

TypeTargetConfidenceTier
ComplianceControlowasp_api_top10-api10100%live
ComplianceControliso27701-a.7.2.1100%live
ComplianceControliso27701-a.7.3.6100%live
ComplianceControlcra-annexi-2100%live
ComplianceControltiber_eu-testing100%live
ComplianceControlowasp_llm_top10-llm08100%live
ComplianceControlai_act-art995%live
ComplianceControlcra-art1495%live

References

  1. https://www.proofpoint.com/us/blog/threat-insight/first-step-initial-access-leads-ransomware
  2. https://therecord.media/hackers-using-follina-windows-zero-day-to-spread-qbot-malware/
  3. https://isc.sans.edu/diary/TA570+Qakbot+Qbot+tries+CVE202230190+Follina+exploit+msmsdt/28728
  4. https://www.microsoft.com/en-us/security/blog/2022/05/09/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
TA530
Actor
TA577
Actor
TA579
Actor
TA547
Actor
TA459
Actor
TA505
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.