TA578

MITRE ATT&CK: G1038 View on attack.mitre.org

Aliases: TA578

Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:01:55

Targeted industries: financial-services retail-and-hospitality transportation-and-logistics

Context

TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.

Detection coverage

  • 33 YARA rules
  • 26 Sigma rules

Malware & tools used

  • Malicious Link (attack-pattern)
  • Search Victim-Owned Websites (attack-pattern)
  • Web Services (attack-pattern)
  • JavaScript (attack-pattern)
  • Bumblebee (malware)
  • IcedID (malware)
  • Latrodectus (malware)

Reports & references

  • proofpoint.com — Bumblebee Is Still Transforming (report)
  • proofpoint.com — Latrodectus Spider Bytes Ice (report)
  • MITRE ATT&CK — G1038 (report)
  • bitsight.com — Latrodectus Are You Coming Back (report)

External references