Hagga
Aliases: Aggah, TH-157
- First seen
- 2021-09-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- individual
- Actor type
- criminal
- Last IoC activity
- 2026-07-19 11:56:31
- Profile updated
- 2026-07-07 11:55:02
Targeted industries: technology-and-telecommunications financial-services
Context
Hagga is believed to have been using Agent Tesla, 2021’s sixth most prevalent malware, to steal sensitive information from his victims since the latter part of 2021.
Reports & references
- Palo Alto Unit 42 — Aggah Campaign Bit Ly Blogspot And Pastebin Used For C2 In Large Scale Campaign (report)
- team-cymru.com — An Analysis Of Infrastructure Linked To The Hagga Threat Actor (report)
- otx.alienvault.com — 62Cfe4Ef3415Be5F83Be81D1 (report)
- team-cymru.com — An Analysis Of Infrastructure Linked To The Hagga Threat Actor (report)