TA575
- First seen
- 2020-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:03:44
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Context
TA575 is a Dridex affiliate tracked by Proofpoint since late 2020. This group distributes malware such as Dridex, Qakbot, and WastedLocker via malicious URLs, Office attachments, and password-protected files. On average, TA575 distributes almost 4,000 messages per campaign impacting hundreds of organizations.
Detection coverage
- 16 YARA rules
Malware & tools used
- Dridex (malware)
- QakBot (malware)
- WastedLocker (malware)
Reports & references
- proofpoint.com — First Step Initial Access Leads Ransomware (report)
- blogs.blackberry.com — Blackberry Prevents Threat Actor Group Ta575 And Dridex Malware (report)
- proofpoint.com — Ta575 Uses Squid Game Lures Distribute Dridex Malware (report)
- zdnet.com — Ta575 Criminal Group Using Squid Game Lures For Dridex Malware (report)