Sobre el grupo
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.
Técnicas (MITRE ATT&CK) 4
Cómo opera el grupo, mapeado por la matriz MITRE ATT&CK y organizado por las fases de un ataque.
Vulnerabilidades explotadas
Ninguna CVE atribuida a este grupo en las fuentes públicas (MITRE ATT&CK). La ausencia de atribución no significa ausencia de actividad.
Infraestructura conocida 56
Indicadores reales (C2, dominios, URLs y hashes) asociados al malware que usa este grupo. Fuente: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
https://precisionproving.com/?v=xg5wadc814Latrodectusthreatfoxhttps://precisionproving.com/?v=nbjj2j8gqyLatrodectusthreatfoxregisteredagentsingeorgia.comLatrodectusthreatfoxprecisionproving.comLatrodectusthreatfoxhttps://fide45felhs.com/work/Latrodectusthreatfoxhttps://agrygamger.com/live/Latrodectusthreatfoxhttps://aplihartom.com/live/Latrodectusthreatfoxregisteredagentsingeorgia.comLatrodectusthreatfoxhttps://kiprihorycom.com/work/Latrodectusthreatfoxhttps://aprettopizza.world/live/Latrodectusthreatfoxhttps://peermangoz.me/live/Latrodectusthreatfoxgitenter.digitalLatrodectusthreatfoxmaialimentosreales.comLatrodectusthreatfoxngb.roLatrodectusthreatfoxnwachambersfamily.comLatrodectusthreatfoxpcl.hamburgLatrodectusthreatfoxquaideazamcollege.comLatrodectusthreatfoxpetx.vetLatrodectusthreatfoxplumbinggurus.comLatrodectusthreatfoxracquetclubofgastonia.comLatrodectusthreatfoxracingoperations.com.auLatrodectusthreatfoxsarahcole.com.auLatrodectusthreatfoxsealaunchservices.comLatrodectusthreatfoxsoftsystems.proLatrodectusthreatfoxstudio-minx.comLatrodectusthreatfoxsurf7seas.comLatrodectusthreatfoxtanahabangmini.netLatrodectusthreatfoxtscd.vnLatrodectusthreatfoxthebookoninvesting.comLatrodectusthreatfoxzeribsglobal.comLatrodectusthreatfox+56 indicadores en total. Míralos todos en la página de IOCs.
Referencias
El grupo TA578 usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.
Conocer el Pentest Autónomo con IA →