TA570
Aliases: DEV-0450
- First seen
- 2018-01-01 00:00:00
- Origin
- RU
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:56:23
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications transportation-and-logistics professional-services
Targeted regions: country_code:us country_code:gb country_code:de country_code:au
Context
One of the most active Qbot malware affiliates, Proofpoint has tracked the large cybercrime threat actor TA570 since 2018.
Detection coverage
- 11 YARA rules
Malware & tools used
- QakBot (malware)
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- proofpoint.com — First Step Initial Access Leads Ransomware (report)
- therecord.media — Hackers Using Follina Windows Zero Day To Spread Qbot Malware (report)
- isc.sans.edu — 28728 (report)