About the group
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.
Techniques (MITRE ATT&CK) 4
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Known infrastructure 56
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
https://precisionproving.com/?v=xg5wadc814Latrodectusthreatfoxhttps://precisionproving.com/?v=nbjj2j8gqyLatrodectusthreatfoxregisteredagentsingeorgia.comLatrodectusthreatfoxprecisionproving.comLatrodectusthreatfoxhttps://fide45felhs.com/work/Latrodectusthreatfoxhttps://agrygamger.com/live/Latrodectusthreatfoxhttps://aplihartom.com/live/Latrodectusthreatfoxregisteredagentsingeorgia.comLatrodectusthreatfoxhttps://kiprihorycom.com/work/Latrodectusthreatfoxhttps://aprettopizza.world/live/Latrodectusthreatfoxhttps://peermangoz.me/live/Latrodectusthreatfoxgitenter.digitalLatrodectusthreatfoxmaialimentosreales.comLatrodectusthreatfoxngb.roLatrodectusthreatfoxnwachambersfamily.comLatrodectusthreatfoxpcl.hamburgLatrodectusthreatfoxquaideazamcollege.comLatrodectusthreatfoxpetx.vetLatrodectusthreatfoxplumbinggurus.comLatrodectusthreatfoxracquetclubofgastonia.comLatrodectusthreatfoxracingoperations.com.auLatrodectusthreatfoxsarahcole.com.auLatrodectusthreatfoxsealaunchservices.comLatrodectusthreatfoxsoftsystems.proLatrodectusthreatfoxstudio-minx.comLatrodectusthreatfoxsurf7seas.comLatrodectusthreatfoxtanahabangmini.netLatrodectusthreatfoxtscd.vnLatrodectusthreatfoxthebookoninvesting.comLatrodectusthreatfoxzeribsglobal.comLatrodectusthreatfox+56 indicators in total. See them all on the IOCs page.
References
TA578 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →