TA578 is a financially motivated cybercrime threat actor tracked since May 2020. It is known for phishing-led malware distribution, particularly abuse of website contact forms and email. TA578 commonly submits copyright- or stolen-image-themed messages through organizations’ contact forms, directing recipients to malicious downloads, and has also used thread-hijacked email conversations and password-protected archives as delivery mechanisms. The actor has distributed Ursnif, IcedID, KPOT Stealer, Buer Loader, BazaLoader, Bumblebee, DanaBot, Latrodectus, and Cobalt Strike. TA578 has used JavaScript-based infection chains and disk-image-based lures to execute malware loaders. In an observed IcedID intrusion, follow-on activity included SOCKS proxying for internal-service scanning, VNC remote access, and Cobalt Strike deployment. TA578 was a prominent distributor of Latrodectus from early 2024.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
105 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TA578 is listed in the detection's annotations.
Listed as an associated threat actor for the JavaScript-execution technique.
Listed as a threat actor associated with the MMC/GrimResource detection analytic.
Listed in annotations as a threat actor associated with the detection context; no specific activity beyond inclusion in the analytic metadata is described.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.