TA2101 is a financially motivated threat actor tracked by Proofpoint and identified as a Maze ransomware affiliate. In campaigns observed between October and November 2019, it targeted organizations in Germany, Italy, and the United States, including IT services, business services, manufacturing, and healthcare organizations. Its malware delivery operations distributed Maze ransomware, Cobalt Strike, and the IcedID banking Trojan. TA2101 uses localized phishing emails that impersonate government agencies and commercial organizations. Its lures have impersonated German federal tax authorities, Italy’s Agenzia Entrate, 1&1 Internet AG, and the United States Postal Service. Themes include tax refunds, tax enforcement notices, and postal notifications. Stolen branding and lookalike domains reinforce the credibility of these messages. The observed infection chain relies on malicious Microsoft Word attachments that persuade recipients to enable macros. Those macros launch PowerShell to download and install the selected payload. German campaigns delivered Cobalt Strike and Maze, Italian campaigns delivered Maze, and a U.S. campaign heavily targeting healthcare delivered IcedID. Maze deployments encrypted victim files and generated ransom notes. TA2101’s country of origin and any state affiliation are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only as a source/reference, not discussed as part of the event itself.
Mentioned for possible infrastructure or campaign-tactic similarities. The connection to NightSpire remains unclear, and the content does not describe TA2101's own operations.
Described as actively using Maze ransomware in campaigns targeting organizations in Germany, Italy, and the United States via malicious email delivery.
An identified affiliate associated with Maze-linked activity, known for malspam campaigns impersonating government agencies; referenced as a potential actor to impersonate Allied Universal in spam using stolen certificates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.