Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
10 malware families

TA866

Also known asasylum_ambuscadeTA866

TA866, also known as Asylum Ambuscade, is a threat actor active since at least 2020. Reporting in the provided content describes it as primarily financially motivated but also involved in cyberespionage; Insikt Group assesses it likely conducts espionage on behalf of the Russian government. The group has targeted bank customers and cryptocurrency traders across North America and Europe, and has conducted espionage against government entities in Europe, Central Asia, and other regions. Proofpoint first publicly reported Asylum Ambuscade in March 2022 after activity targeting European government staff assisting Ukrainian refugees. TA866 operations commonly begin via malspam, spearphishing, malvertising, SEO poisoning, and traffic distribution systems including 404 TDS and TAG-124/KongTuke. Observed delivery methods include thread hijacking, malicious hyperlinks, PDF and Microsoft Publisher attachments, OneDrive-hosted JavaScript, malicious Google ads, and fake browser-update style lures. In espionage-focused activity, the group has used malicious Excel attachments and Follina (CVE-2022-30190). The actor is closely associated with staged downloader and surveillance tooling including JavaScript downloaders, SunSeed, WasabiSeed, Screenshotter, AHK Bot, and NODEBOT. WasabiSeed and SunSeed establish persistence and retrieve additional MSI payloads. Screenshotter is used to capture and exfiltrate desktop screenshots, apparently to triage victims before further action. AHK Bot is a modular AutoHotKey-based malware family used for persistence, system and domain enumeration, screenshot capture, keystroke logging, browser credential theft, hVNC deployment, and deployment or removal of remote access software. NODEBOT was introduced as a Node.js equivalent to AHK Bot. TA866 has also been linked to Resident backdoor development and to WarmCookie/BadSpace activity; Talos assessed WarmCookie activity is related to prior TA866 intrusion activity and noted likely shared authorship with Resident. PS1Bot was also assessed to share technical overlaps with AHK Bot previously used by TA866. Post-compromise activity includes reconnaissance with native Windows tools such as net group, nltest, ipconfig, whoami, and systeminfo, as well as utilities such as AdFind and network scanners. Follow-on payloads observed in TA866-linked activity include Rhadamanthys, Cobalt Strike, CSharp-Streamer-RAT, Resident, AnyDesk, TeamViewer, Remote Utilities, and in some reporting Remote Utilities RAT. Proofpoint attributed post-exploitation tooling in Rhadamanthys campaigns to TA866, and Talos reported limited cases involving additional malware deployment. The group has also been reported using shared infrastructure or services, including TAG-124/KongTuke and 404 TDS, and leveraging relationships with other actors such as TA571 for spam distribution. Aliases directly mentioned in the content are TA866 and Asylum Ambuscade. Proofpoint also referred to a TA866 activity cluster as Screentime.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Banks
  • Financial Services
  • Government & Administration
MITRE ATT&CK

Tradecraft

30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics44 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589
Gather Victim Identity Information
T1589.002
Email Addresses
TA0042
Resource Development
2 techniques
T1586
Compromise Accounts
T1586.002
Email Accounts
T1608
Stage Capabilities
T1608.006
SEO Poisoning
TA0001
Initial Access
1 technique
T1566×2
Phishing
T1566.001
Spearphishing Attachment
T1566.002×2
Spearphishing Link
TA0002
Execution
5 techniques
T1047
Windows Management Instrumentation
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1059.003
Windows Command Shell
T1059.007
JavaScript
T1197
BITS Jobs
T1204
User Execution
T1204.002
Malicious File
TA0003
Persistence
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1197
BITS Jobs
TA0004
Privilege Escalation
1 technique
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
TA0005
Stealth
2 techniques
T1197
BITS Jobs
T1218
System Binary Proxy Execution
T1218.007
Msiexec
T1218.011
Rundll32
TA0007
Discovery
10 techniques
T1007
System Service Discovery
T1016
System Network Configuration Discovery
T1018
Remote System Discovery
T1033
System Owner/User Discovery
T1057
Process Discovery
T1069
Permission Groups Discovery
T1069.002
Domain Groups
T1082
System Information Discovery
T1124
System Time Discovery
T1482
Domain Trust Discovery
T1518
Software Discovery
T1518.001
Security Software Discovery
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1105×2
Ingress Tool Transfer
T1219
Remote Access Tools
IOCS

Observables

49 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping30

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal10

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables49

Domains, IPs, and hashes tied to this actor, refreshed continuously.

TA866 | Mallory