TA578

APT / StateG1038
Techniques (MITRE ATT&CK)4
SourceMITRE ATT&CK
0

Vexday analysis

TA578 é um agente de ameaça que utiliza formulários de contato e e-mail para iniciar comunicações com vítimas e distribuir malware, incluindo Latrodectus, IcedID e Bumblebee. O grupo é rastreado pelo MITRE ATT&CK sob o identificador G1038, com 4 técnicas documentadas em sua matriz.

Techniques (MITRE ATT&CK) 4

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Resource development

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 45

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

domaingitenter.digitalLatrodectusthreatfox
domainmaialimentosreales.comLatrodectusthreatfox
domainngb.roLatrodectusthreatfox
domainnwachambersfamily.comLatrodectusthreatfox
domainpcl.hamburgLatrodectusthreatfox
domainquaideazamcollege.comLatrodectusthreatfox
domainpetx.vetLatrodectusthreatfox
domainplumbinggurus.comLatrodectusthreatfox
domainracingoperations.com.auLatrodectusthreatfox
domainracquetclubofgastonia.comLatrodectusthreatfox
domainsealaunchservices.comLatrodectusthreatfox
domainsarahcole.com.auLatrodectusthreatfox
domainstudio-minx.comLatrodectusthreatfox
domainsoftsystems.proLatrodectusthreatfox
domainsurf7seas.comLatrodectusthreatfox
domaintanahabangmini.netLatrodectusthreatfox
domainthebookoninvesting.comLatrodectusthreatfox
domaintscd.vnLatrodectusthreatfox
domainvin2.roLatrodectusthreatfox
domainwaltonsoftware.comLatrodectusthreatfox
domainzeribsglobal.comLatrodectusthreatfox
domainfocusspo.comLatrodectusthreatfox
domainmarebnb.comLatrodectusthreatfox
domainpyebrook.comLatrodectusthreatfox
domainsamarkegypt.comLatrodectusthreatfox
domaincaramdistribuciones.com.arLatrodectusthreatfox
domaincmla.blogLatrodectusthreatfox
domaincursohenfil.com.brLatrodectusthreatfox
domaincydesys.comLatrodectusthreatfox
domaindokonalebydleni.czLatrodectusthreatfox

+45 indicators in total. See them all on the IOCs page.

TA578 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →