TA577

MITRE ATT&CK: G1037 View on attack.mitre.org

Aliases: Hive0118, TA577

First seen
2020-01-01 00:00:00
Origin
RU
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Last IoC activity
2026-07-22 01:23:26
Profile updated
2026-07-07 12:03:48

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:us country_code:gb country_code:au country_code:ca

Context

TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in 2023.

Detection coverage

  • 197 YARA rules
  • 57 Sigma rules

Malware & tools used

Reports & references

  • proofpoint.com — First Step Initial Access Leads Ransomware (report)
  • thehackernews.com — Ransomware Attackers Partnering With (report)
  • itpro.com — Ransomware Criminals Look To Other Hackers To Provide Them With Network (report)
  • exchange.xforce.ibmcloud.com — Guid:1Dda890Fa2662Ed26B451C703E922315 (report)
  • MITRE ATT&CK — G1037 (report)
  • proofpoint.com — Latrodectus Spider Bytes Ice (report)

Attributed from

  • Pikabot Distribution Campaigns 2023 (campaign)
  • TA577 NTLM Credential Theft Attacks (campaign)

External references