TA551

APT / StateG0127 ↗
Techniques (MITRE ATT&CK)14
SourceMITRE ATT&CK
0
Also known as:ATK236G0127GOLD CABINMonster LibraShakthakShathak

About the group

TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity20
Impact: High
T1566.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionWindows CommandShell

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 14

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 636

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

md5_hashef5ebe165dc61a588e448f5a045f545dSliverthreatfox
sha1_hashfb7fc0a4b77adfe1388efd7d08e113ee6abc142eSliverthreatfox
sha256_hash01c6597a9d807338577300a4c861509021b161784c7997d70e4bd44d4da2c059Sliverthreatfox
urlhttp://http:/f.pylrk.cc/HaKi2ufpiQ8AeVTZ/hostSliverthreatfox
sha1_hash2688fb01200335f8a1f0239b5f7ccbf9263426ceSliverthreatfox
md5_hashbe02c9890e938e672165c1c10bc99bb2Sliverthreatfox
sha1_hash0b155f94bce42cde68d41230f5f59bd3fc46dbc8Sliverthreatfox
md5_hash19a878708605994686c72a7dd3652d07Sliverthreatfox
sha256_hash045e0dc95dbfa3ce9d457810c24751e95c8416762a4452e28ff29bde1c58f8f8Sliverthreatfox
sha256_hash9f51ab6d2c23a1d89f3fdda78243e2a975984e9ea496c6ecc95d155fafafcfd6Sliverthreatfox
urlhttp://46.19.140.40:8443/SecurityHealthSys.exeSliverurlhaus
urlhttp://46.19.140.40:8443/loader.exeSliverurlhaus
sha256_hash2823619d9775c348c53807e986feee0c6862ee7350e2d0e4edc6954b2de73c02Sliverthreatfox
ip:port46.151.182.182:31337Sliverthreatfox
ip:port159.89.28.205:31337Sliverthreatfox
ip:port156.251.16.152:31337Sliverthreatfox
ip:port154.219.114.14:8443Sliverthreatfox
ip:port45.130.167.184:31337Sliverthreatfox
ip:port207.148.73.17:31337Sliverthreatfox
ip:port196.251.121.120:31337Sliverthreatfox
ip:port152.67.199.142:10443Sliverthreatfox
ip:port137.184.126.9:31337Sliverthreatfox
ip:port51.178.49.164:31337Sliverthreatfox
ip:port187.145.62.206:31337Sliverthreatfox
md5_hash76d2b36de3696996b07353c29a06698aSliverthreatfox
sha1_hashd146f59f4dcfe845fe28ed91b3eed530e78947a8Sliverthreatfox
sha256_hashc1e184615241fe69db3bf4093a22c7c0bf5d6072d2f51e558142b844e871084fSliverthreatfox
ip:port67.215.229.22:31337Sliverthreatfox
ip:port5.230.253.51:31337Sliverthreatfox
ip:port185.130.46.90:443Sliverthreatfox

+636 indicators in total. See them all on the IOCs page.

TA551 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →