TA866, also known as Asylum Ambuscade, is a threat actor active since at least 2020 that conducts primarily financially motivated intrusion activity and has also been linked to cyberespionage operations. The actor has been associated with campaigns targeting bank customers, cryptocurrency traders, small and medium businesses, and organizations across multiple sectors, as well as government entities in Europe and Central Asia. Reporting has also linked the group to targeting European government personnel involved in support for Ukrainian refugees. Multiple assessments indicate likely Russian nexus, including Russian-language code comments and analysis assessing espionage activity may be conducted on behalf of the Russian government. TA866 commonly gains initial access through malspam, thread hijacking, malicious attachments, malicious hyperlinks, malvertising, SEO poisoning, and traffic distribution systems including 404 TDS and TAG-124-linked ecosystems. Delivery chains have used JavaScript downloaders, MSI packages, and staged script-based loaders. Custom tooling associated with the actor includes WasabiSeed and Screenshotter, with broader tooling overlap involving AHK Bot and related malware families. WasabiSeed has been used to establish persistence and retrieve follow-on payloads, while Screenshotter enables periodic desktop capture for victim triage. AHK Bot provides modular post-compromise capability including system profiling, domain identification, screenshot capture, keylogging, browser credential theft, and deployment or removal of additional tooling. Post-compromise activity includes reconnaissance with native Windows utilities and tools such as AdFind and network scanners, along with selective deployment of remote access software and additional malware. Follow-on payloads observed in TA866-linked intrusions include Rhadamanthys, Resident, WarmCookie, CSharp-Streamer-RAT, Cobalt Strike, and commercial remote administration tools. TA866 has also been linked to in-memory execution of secondary payloads, credential theft from browsers, screenshot collection, persistence via startup shortcuts or scheduled tasks, and use of shared or rented initial-access infrastructure operated by other actors. The actor is notable for blending crimeware and espionage tradecraft. Financially motivated campaigns have emphasized victim triage, credential theft, and access enablement, while espionage-linked operations have focused on government targets and theft of confidential information and webmail credentials. TA866 has also been associated with broader criminal ecosystems involving spam distributors, traffic distribution services, and malware delivery partnerships.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
49 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an APT customer of KongTuke's infection distribution service.
Named as a threat actor/activity cluster associated with use of TAG-124 shared traffic distribution infrastructure (per Recorded Future, as cited in the content). No additional operational details provided in this content.
Referenced as a named threat actor that has leveraged KongTuke/TAG-124 infrastructure for follow-on malware delivery.
Referenced as an activity cluster that has leveraged KongTuke/TAG-124 infrastructure for follow-on malware delivery after initial access/traffic redirection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.