TA551

MITRE ATT&CK: G0127 View on attack.mitre.org

Aliases: GOLD CABIN, Shathak, Shakthak, TA551, ATK236, Monster Libra

First seen
2018-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Related IoCs
228 (182 malicious)
Last IoC activity
2026-09-02 00:39:57
Profile updated
2026-07-07 12:00:06

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:us country_code:de country_code:it country_code:jp

Context

TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns.

Recent IoC activity

182 malicious indicators in Maltiverse are attributed to TA551 (G0127). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname zaheeruddinconsultants.org 2026-09-03 2
hostname centroathenea.com 2026-09-03 2
hostname megadexcargo.com.my 2026-09-03 2
hostname graphel.com.br 2026-09-03 2
hostname cuistokids.fr 2026-09-03 2
hostname levelmultimedia.com 2026-09-03 2
hostname culversmenus.com 2026-09-03 2
hostname dailyflap.com 2026-09-03 2
hostname elsultanstid.com 2026-09-03 3
hostname teyco.com.sv 2026-09-03 2
hostname comradedata.com.ng 2026-09-03 2
hostname temeron.de 2026-09-03 2
hostname labcom.com.mx 2026-09-03 3
hostname shopallaboutjewelry.com 2026-09-03 2
hostname theotech.com.py 2026-09-03 2
hostname perfectafoundation.com 2026-09-03 2
hostname worldstarstv.com 2026-09-03 2
hostname scraptomoney.com 2026-09-03 2
hostname cherryberryrms.com 2026-09-03 2
hostname broadmaxshop.com 2026-09-03 2

Detection coverage

  • 39 YARA rules
  • 283 Sigma rules

Malware & tools used

  • Regsvr32 (attack-pattern)
  • Email Addresses (attack-pattern)
  • Malicious File (attack-pattern)
  • Rundll32 (attack-pattern)
  • Steganography (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Domain Generation Algorithms (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Web Protocols (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Mshta (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Masquerading (attack-pattern)
  • Sliver (malware)
  • Ursnif (malware)
  • IcedID (malware)
  • Valak (malware)
  • QakBot (malware)

Reports & references

  • secureworks.com — Gold Cabin (report)
  • MITRE ATT&CK — G0127 (report)
  • Palo Alto Unit 42 — Monsterlibra (report)
  • Palo Alto Unit 42 — Ta551 Shathak Icedid (report)
  • Palo Alto Unit 42 — Valak Evolution (report)

External references