TA547

First seen
2017-11-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:01:05

Targeted industries: financial-services

Targeted regions: country_code:au country_code:de country_code:gb country_code:it

Context

TA547 is responsible for many other campaigns since at least November 2017. The other campaigns by the actor were often localized to countries such as Australia, Germany, the United Kingdom, and Italy. Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.

Reports & references

  • thaicert.or.th — Threat Group Cards V2.0 (report)

External references