TA575TA575
Also known as: TA575
Known aliases
1
Profile
TA575 is a Dridex affiliate tracked by Proofpoint since late 2020. This group distributes malware such as Dridex, Qakbot, and WastedLocker via malicious URLs, Office attachments, and password-protected files. On average, TA575 distributes almost 4,000 messages per campaign impacting hundreds of organizations.
Aliases· 1
TA575
Compliance frameworks testing this (incoming)3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| ComplianceControl | ai_act-art9 | 100% | live |
| ComplianceControl | tiber_eu-testing | 100% | live |
| ComplianceControl | tiber_eu-generic | 100% | live |
References
- https://blogs.blackberry.com/en/2021/08/blackberry-prevents-threat-actor-group-ta575-and-dridex-malware
- https://www.proofpoint.com/us/blog/threat-insight/ta575-uses-squid-game-lures-distribute-dridex-malware
- https://www.zdnet.com/article/ta575-criminal-group-using-squid-game-lures-for-dridex-malware/
- https://www.proofpoint.com/us/blog/threat-insight/first-step-initial-access-leads-ransomware
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.