RU

TA577TA577

Also known as: Hive0118 · TA577

Origin
RU
Known aliases
2

Profile

TA577 is a prolific cybercrime threat actor tracked by Proofpoint since mid-2020. This actor conducts broad targeting across various industries and geographies, and Proofpoint has observed TA577 deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike.

Aliases· 2

Hive0118TA577

Compliance frameworks testing this (incoming)5

TypeTargetConfidenceTier
ComplianceControlpci_dss_v4-r2100%live
ComplianceControlpci_dss_v4-r6100%live
ComplianceControltiber_eu-generic100%live
ComplianceControlcra-art14100%live
ComplianceControlai_act-art73100%live

References

  1. https://www.proofpoint.com/us/blog/threat-insight/first-step-initial-access-leads-ransomware
  2. https://thehackernews.com/2021/06/ransomware-attackers-partnering-with.html
  3. https://www.itpro.com/security/ransomware/359919/ransomware-criminals-look-to-other-hackers-to-provide-them-with-network
  4. https://exchange.xforce.ibmcloud.com/threat-group/guid:1dda890fa2662ed26b451c703e922315

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
TA578
Actor
TA579
Actor
TA570
Actor
TA547
Actor
TA571
Actor
TA575
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.