Hagga

Aliases: Aggah, TH-157

First seen
2021-09-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
individual
Actor type
criminal
Last IoC activity
2026-07-19 11:56:31
Profile updated
2026-07-07 11:55:02

Targeted industries: technology-and-telecommunications financial-services

Context

Hagga is believed to have been using Agent Tesla, 2021’s sixth most prevalent malware, to steal sensitive information from his victims since the latter part of 2021.

Reports & references

  • Palo Alto Unit 42 — Aggah Campaign Bit Ly Blogspot And Pastebin Used For C2 In Large Scale Campaign (report)
  • team-cymru.com — An Analysis Of Infrastructure Linked To The Hagga Threat Actor (report)
  • otx.alienvault.com — 62Cfe4Ef3415Be5F83Be81D1 (report)
  • team-cymru.com — An Analysis Of Infrastructure Linked To The Hagga Threat Actor (report)

External references