TA505
MITRE ATT&CK: G0092 View on attack.mitre.org
Aliases: Hive0065, Spandex Tempest, CHIMBORAZO, SectorJ04, SectorJ04 Group, GRACEFUL SPIDER, GOLD TAHOE, Dudear, ATK103, TA505, MONTY SPIDER
- First seen
- 2014-01-01 00:00:00
- Origin
- RU
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Related IoCs
- 24 (22 malicious)
- Last IoC activity
- 2026-08-30 05:00:12
- Profile updated
- 2026-07-07 12:34:12
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications
Context
TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.
Recent IoC activity
22 malicious indicators in Maltiverse are attributed to TA505 (G0092). The 20 most recently updated:
Detection coverage
- 183 YARA rules
- 777 Sigma rules
Malware & tools used
- Email Account (attack-pattern)
- Domains (attack-pattern)
- Mark-of-the-Web Bypass (attack-pattern)
- Msiexec (attack-pattern)
- Modify Registry (attack-pattern)
- Tool (attack-pattern)
- Malicious File (attack-pattern)
- Fast Flux DNS (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Software Packing (attack-pattern)
- Credentials In Files (attack-pattern)
- Visual Basic (attack-pattern)
- JavaScript (attack-pattern)
- Malicious Link (attack-pattern)
- Upload Malware (attack-pattern)
- Rundll32 (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Command Obfuscation (attack-pattern)
- Permission Groups Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Malware (attack-pattern)
- Domain Accounts (attack-pattern)
- Code Signing (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
Exploited vulnerabilities
- CVE-2020-1472 (vulnerability)
Related threat objects
- MONTY SPIDER (threat-actor)
- Lace Tempest (threat-actor)
Reports & references
- bleepingcomputer.com — Ta505 Group Adopts New Servhelper Backdoor And Flawedgrace Rat (report)
- proofpoint.com — Ta505 Timeline Final4 0.Png (report)
- proofpoint.com — Threat Actor Profile Ta505 Dridex Globeimposter (report)
- cybereason.com — Threat Actor Ta505 Targets Financial Enterprises Using Lolbins And A New Backdoor Malware (report)
- e.cyberint.com — Cyberint Legit%20Remote%20Access%20Tools%20Turn%20Into%20Threat%20Actors'%20Tools Report (report)
- threatpost.com — 140792 (report)
- blog.yoroi.company — The Stealthy Email Stealer In The Ta505 Arsenal (report)
- threatrecon.nshc.net — Sectorj04 Groups Increased Activity In 2019 (report)
- proofpoint.com — Ta505 Distributes New Sdbbot Remote Access Trojan Get2 Downloader (report)
- blueliv.com — Servhelper Evolution And New Ta505 Campaigns (report)
- telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
- telekom.com — Cybersecurity Ta505 Returns With A New Bag Of Tricks 602104 (report)
- secureworks.com — Gold Tahoe (report)
- telekom.com — Eager Beaver A Short Overview Of The Restless Threat Actor Ta505 609546 (report)
- blog.fox-it.com — Ta505 A Brief History Of Their Time (report)
- secureworks.com — How Cyber Adversaries Are Adapting To Exploit The Global Pandemic (report)
- cyberthreat.thalesgroup.com — Atk103 (report)
- securityintelligence.com — Ta505 Continues To Infect Networks With Sdbbot Rat (report)
- tenable.com — Cve 2020 1472 Advanced Persistent Threat Actors Use Zerologon Vulnerability In Exploit Chain (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- MITRE ATT&CK — G0092 (report)
- research.nccgroup.com — Ta505 A Brief History Of Their Time (report)
- web.archive.org — Ta505 Continues To Infect Networks With Sdbbot Rat (report)
- fsec.or.kr — 1382.Do (report)
Attributed from
- Clop MOVEit Transfer Vulnerability Exploitation (campaign)
External references
- mitre-attack — G0092
- Hive0065
- Spandex Tempest
- CHIMBORAZO
- Korean FSI TA505 2020
- IBM TA505 April 2020
- Microsoft Threat Actor Naming July 2023
- Proofpoint TA505 Sep 2017
- Proofpoint TA505 June 2018
- Proofpoint TA505 Jan 2019
- NCC Group TA505
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy