TA577
MITRE ATT&CK: G1037 View on attack.mitre.org
Aliases: Hive0118, TA577
- First seen
- 2020-01-01 00:00:00
- Origin
- RU
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Last IoC activity
- 2026-07-22 01:23:26
- Profile updated
- 2026-07-07 12:03:48
Targeted industries: financial-services technology-and-telecommunications government-and-public-sector
Targeted regions: country_code:us country_code:gb country_code:au country_code:ca
Context
TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in 2023.
Detection coverage
- 197 YARA rules
- 57 Sigma rules
Malware & tools used
- JavaScript (attack-pattern)
- Windows Command Shell (attack-pattern)
- Embedded Payloads (attack-pattern)
- Email Accounts (attack-pattern)
- Malicious Link (attack-pattern)
- Spearphishing Link (attack-pattern)
- IcedID (malware)
- SystemBC (Windows) (malware)
- SmokeLoader (malware)
- Snifula (malware)
- Cobalt Strike (malware)
- Pikabot (malware)
- Latrodectus (malware)
- QakBot (malware)
Reports & references
- proofpoint.com — First Step Initial Access Leads Ransomware (report)
- thehackernews.com — Ransomware Attackers Partnering With (report)
- itpro.com — Ransomware Criminals Look To Other Hackers To Provide Them With Network (report)
- exchange.xforce.ibmcloud.com — Guid:1Dda890Fa2662Ed26B451C703E922315 (report)
- MITRE ATT&CK — G1037 (report)
- proofpoint.com — Latrodectus Spider Bytes Ice (report)
Attributed from
- Pikabot Distribution Campaigns 2023 (campaign)
- TA577 NTLM Credential Theft Attacks (campaign)