Get2

MITRE ATT&CK: S0460 View on attack.mitre.org

Aliases: FRIENDSPEAK, GetandGo, Get2

First seen
2019-06-01 00:00:00
Malware type
downloader
Family
Malware family
Operating systems
windows
Related IoCs
87 (15 malicious)
Last IoC activity
2026-09-02 00:38:49
Profile updated
2026-07-07 12:41:18

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Context

Get2 is a downloader written in C++ that has been used by TA505 to deliver FlawedGrace, FlawedAmmyy, Snatch and SDBbot.

Recent IoC activity

15 malicious indicators in Maltiverse are attributed to Get2 (S0460). The 15 most recently updated:

TypeIndicatorUpdatedSources
hostname scanotec.dk 2026-09-03 2
hostname seiyuu.ne.jp 2026-09-02 1
hostname unser-en.de 2026-09-02 1
hostname organic-harmony.com 2026-09-02 1
hostname washington-twp.com 2026-09-02 1
hostname cumc-hmb.com 2026-05-31 1
URL http://reachtherapyllc.com/1q0hts9.html 2026-01-01 1
file sample P002983_37478.xls 2025-12-27 1
URL http://gmy.su/:jjOab 2025-11-14 1
URL http://ntskeptics.org/ukpg.html 2025-11-11 1
URL http://4sv.xyz/advertisment.php 2025-10-19 1
URL http://gmy.su/:jlOab 2025-10-02 1
file sample 585ec4c541d0185e467bff79d611e7c1.dll 2025-09-30 1
URL http://mosgid.ru/~mosgid/u4mt.html 2025-09-22 1
URL http://www.epower-adv.it/wounding.php 2025-07-17 1

Detection coverage

  • 1 YARA rules
  • 177 Sigma rules

Malware & tools used

  • Dynamic-link Library Injection (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Web Protocols (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Get2_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • proofpoint.com — Ta505 Distributes New Sdbbot Remote Access Trojan Get2 Downloader (report)
  • telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
  • telekom.com — Cybersecurity Ta505 Returns With A New Bag Of Tricks 602104 (report)
  • secureworks.com — Gold Tahoe (report)
  • telekom.com — Eager Beaver A Short Overview Of The Restless Threat Actor Ta505 609546 (report)
  • blog.fox-it.com — Ta505 A Brief History Of Their Time (report)
  • github.com — Tafof Unpacker (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 009 (report)
  • hornetsecurity.com — Clop Clop Ta505 Html Malspam Analysis (report)
  • telekom.com — Inside Of Cl0P S Ransomware Operation 615824 (report)
  • blog.intel471.com — A Brief History Of Ta505 (report)
  • intel471.com — A Brief History Of Ta505 (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • proofpoint.com — Coronavirus Threat Landscape Update (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Get2 (report)
  • intel471.com — Ta505 Get2 Loader Malware December 2020 (report)
  • github.com — Malware%20Analysis%2004 10 2019.Md (report)
  • elis531989.medium.com — Funtastic Packers And Where To Find Them 41429A7Ef9A7 (report)
  • blog.intel471.com — Flowspec Ta505S Bulletproof Hoster Of Choice (report)
  • goggleheadedhacker.com — 13 (report)
  • MITRE ATT&CK — S0460 (report)

External references