TA578

APT / StateG1038 ↗
Techniques (MITRE ATT&CK)4
SourceMITRE ATT&CK
0

About the group

TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.

Techniques (MITRE ATT&CK) 4

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Resource development

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 56

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

urlhttps://precisionproving.com/?v=xg5wadc814Latrodectusthreatfox
urlhttps://precisionproving.com/?v=nbjj2j8gqyLatrodectusthreatfox
domainregisteredagentsingeorgia.comLatrodectusthreatfox
domainprecisionproving.comLatrodectusthreatfox
urlhttps://fide45felhs.com/work/Latrodectusthreatfox
urlhttps://agrygamger.com/live/Latrodectusthreatfox
urlhttps://aplihartom.com/live/Latrodectusthreatfox
domainregisteredagentsingeorgia.comLatrodectusthreatfox
urlhttps://kiprihorycom.com/work/Latrodectusthreatfox
urlhttps://aprettopizza.world/live/Latrodectusthreatfox
urlhttps://peermangoz.me/live/Latrodectusthreatfox
domaingitenter.digitalLatrodectusthreatfox
domainmaialimentosreales.comLatrodectusthreatfox
domainngb.roLatrodectusthreatfox
domainnwachambersfamily.comLatrodectusthreatfox
domainpcl.hamburgLatrodectusthreatfox
domainquaideazamcollege.comLatrodectusthreatfox
domainpetx.vetLatrodectusthreatfox
domainplumbinggurus.comLatrodectusthreatfox
domainracquetclubofgastonia.comLatrodectusthreatfox
domainracingoperations.com.auLatrodectusthreatfox
domainsarahcole.com.auLatrodectusthreatfox
domainsealaunchservices.comLatrodectusthreatfox
domainsoftsystems.proLatrodectusthreatfox
domainstudio-minx.comLatrodectusthreatfox
domainsurf7seas.comLatrodectusthreatfox
domaintanahabangmini.netLatrodectusthreatfox
domaintscd.vnLatrodectusthreatfox
domainthebookoninvesting.comLatrodectusthreatfox
domainzeribsglobal.comLatrodectusthreatfox

+56 indicators in total. See them all on the IOCs page.

TA578 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →