TA571

First seen
2019-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 12:15:53

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

TA571 is a spam distributor actor known for delivering a variety of malware, including DarkGate, NetSupport RAT, and information stealers. They use phishing emails with macro-enabled attachments to spread malicious PDFs containing rogue OneDrive links. TA571 has been observed using unique filtering techniques with intermediary "gates" to target specific users and bypass automated sandboxing. Proofpoint assesses with high confidence that TA571 infections can lead to ransomware.

Reports & references

  • proofpoint.com — Security Brief Ta571 Delivers Icedid Forked Loader (report)
  • proofpoint.com — Clipboard Compromise Powershell Self Pwn (report)

Attributed from

  • PowerShell User Execution Social Engineering Campaign (TA571, ClearFake, ClickFix) (campaign)

External references