TA575

First seen
2020-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:03:44

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Context

TA575 is a Dridex affiliate tracked by Proofpoint since late 2020. This group distributes malware such as Dridex, Qakbot, and WastedLocker via malicious URLs, Office attachments, and password-protected files. On average, TA575 distributes almost 4,000 messages per campaign impacting hundreds of organizations.

Detection coverage

  • 16 YARA rules

Malware & tools used

Reports & references

  • proofpoint.com — First Step Initial Access Leads Ransomware (report)
  • blogs.blackberry.com — Blackberry Prevents Threat Actor Group Ta575 And Dridex Malware (report)
  • proofpoint.com — Ta575 Uses Squid Game Lures Distribute Dridex Malware (report)
  • zdnet.com — Ta575 Criminal Group Using Squid Game Lures For Dridex Malware (report)

External references