TA570

Aliases: DEV-0450

First seen
2018-01-01 00:00:00
Origin
RU
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:56:23

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications transportation-and-logistics professional-services

Targeted regions: country_code:us country_code:gb country_code:de country_code:au

Context

One of the most active Qbot malware affiliates, Proofpoint has tracked the large cybercrime threat actor TA570 since 2018.

Detection coverage

  • 11 YARA rules

Malware & tools used

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • proofpoint.com — First Step Initial Access Leads Ransomware (report)
  • therecord.media — Hackers Using Follina Windows Zero Day To Spread Qbot Malware (report)
  • isc.sans.edu — 28728 (report)

External references