TA505

MITRE ATT&CK: G0092 View on attack.mitre.org

Aliases: Hive0065, Spandex Tempest, CHIMBORAZO, SectorJ04, SectorJ04 Group, GRACEFUL SPIDER, GOLD TAHOE, Dudear, ATK103, TA505, MONTY SPIDER

First seen
2014-01-01 00:00:00
Origin
RU
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Related IoCs
24 (22 malicious)
Last IoC activity
2026-08-30 05:00:12
Profile updated
2026-07-07 12:34:12

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications

Context

TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.

Recent IoC activity

22 malicious indicators in Maltiverse are attributed to TA505 (G0092). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 9909775be4d2e9cd06957e9819e77d0e.xls 2026-08-30 1
file sample sub_309c15c52e4d.bin 2026-08-29 2
file sample sub_4bda777159fc.bin 2026-08-04 2
file sample sub_fa28b59eb0cc.bin 2026-05-24 1
file sample sub_75e8bd6d7efc.bin 2026-05-24 1
file sample sub_e61ad845dbc4.bin 2026-05-24 1
file sample sub_02e4e13a4471.bin 2026-05-24 1
file sample submitted timesheet Sept 2020_0987.xls 2026-05-03 1
file sample str_join2.bin 2026-04-22 1
file sample 749_The Peoples Pension (01-Oct-19 to 31-May-20) (Set 3).xls 2026-03-27 1
file sample CHQ020114862.xls 2026-03-26 1
file sample 2020_06_22_harvest_expense_report.xls 2026-03-07 1
file sample CLBS_0011_1220.docx 2025-11-02 1
file sample stGui2.dll 2025-11-02 1
file sample Q2 2020 Sales Source File.xls 2025-11-01 1
file sample 17291fc45dc342a6ce4309dd4b77cd094c564fad14c212bca827770daf7207d4 2025-11-01 1
file sample d5c0467203c0f15dc699f18b1f1462a992531b8b812fa1df7802193d1e9b0516 2025-11-01 1
file sample stGui1.dll 2025-11-01 1
file sample rgoc2.bin 2025-11-01 1
file sample bd8669b5ad88a654a65db9579da4f2990d725261bee958ec0c7d6db3f112e170c50ea5541a81b... 2025-10-18 2

Detection coverage

  • 183 YARA rules
  • 777 Sigma rules

Malware & tools used

  • Email Account (attack-pattern)
  • Domains (attack-pattern)
  • Mark-of-the-Web Bypass (attack-pattern)
  • Msiexec (attack-pattern)
  • Modify Registry (attack-pattern)
  • Tool (attack-pattern)
  • Malicious File (attack-pattern)
  • Fast Flux DNS (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Software Packing (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Visual Basic (attack-pattern)
  • JavaScript (attack-pattern)
  • Malicious Link (attack-pattern)
  • Upload Malware (attack-pattern)
  • Rundll32 (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Permission Groups Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Malware (attack-pattern)
  • Domain Accounts (attack-pattern)
  • Code Signing (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)

Exploited vulnerabilities

  • CVE-2020-1472 (vulnerability)

Related threat objects

Reports & references

  • bleepingcomputer.com — Ta505 Group Adopts New Servhelper Backdoor And Flawedgrace Rat (report)
  • proofpoint.com — Ta505 Timeline Final4 0.Png (report)
  • proofpoint.com — Threat Actor Profile Ta505 Dridex Globeimposter (report)
  • cybereason.com — Threat Actor Ta505 Targets Financial Enterprises Using Lolbins And A New Backdoor Malware (report)
  • e.cyberint.com — Cyberint Legit%20Remote%20Access%20Tools%20Turn%20Into%20Threat%20Actors'%20Tools Report (report)
  • threatpost.com — 140792 (report)
  • blog.yoroi.company — The Stealthy Email Stealer In The Ta505 Arsenal (report)
  • threatrecon.nshc.net — Sectorj04 Groups Increased Activity In 2019 (report)
  • proofpoint.com — Ta505 Distributes New Sdbbot Remote Access Trojan Get2 Downloader (report)
  • blueliv.com — Servhelper Evolution And New Ta505 Campaigns (report)
  • telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
  • telekom.com — Cybersecurity Ta505 Returns With A New Bag Of Tricks 602104 (report)
  • secureworks.com — Gold Tahoe (report)
  • telekom.com — Eager Beaver A Short Overview Of The Restless Threat Actor Ta505 609546 (report)
  • blog.fox-it.com — Ta505 A Brief History Of Their Time (report)
  • secureworks.com — How Cyber Adversaries Are Adapting To Exploit The Global Pandemic (report)
  • cyberthreat.thalesgroup.com — Atk103 (report)
  • securityintelligence.com — Ta505 Continues To Infect Networks With Sdbbot Rat (report)
  • tenable.com — Cve 2020 1472 Advanced Persistent Threat Actors Use Zerologon Vulnerability In Exploit Chain (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G0092 (report)
  • research.nccgroup.com — Ta505 A Brief History Of Their Time (report)
  • web.archive.org — Ta505 Continues To Infect Networks With Sdbbot Rat (report)
  • fsec.or.kr — 1382.Do (report)

Attributed from

  • Clop MOVEit Transfer Vulnerability Exploitation (campaign)

External references