TA578
MITRE ATT&CK: G1038 View on attack.mitre.org
Aliases: TA578
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:01:55
Targeted industries: financial-services retail-and-hospitality transportation-and-logistics
Context
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.
Detection coverage
- 33 YARA rules
- 26 Sigma rules
Malware & tools used
- Malicious Link (attack-pattern)
- Search Victim-Owned Websites (attack-pattern)
- Web Services (attack-pattern)
- JavaScript (attack-pattern)
- Bumblebee (malware)
- IcedID (malware)
- Latrodectus (malware)
Reports & references
- proofpoint.com — Bumblebee Is Still Transforming (report)
- proofpoint.com — Latrodectus Spider Bytes Ice (report)
- MITRE ATT&CK — G1038 (report)
- bitsight.com — Latrodectus Are You Coming Back (report)