TA571 is a financially motivated cybercriminal threat actor best known as a high-volume spam distributor and financially motivated initial access group. Since at least 2019, it has operated large-scale malspam campaigns to deliver malware for downstream criminal customers and has been closely associated with spam botnet activity, the 404TDS traffic distribution system, and broad malware distribution operations. TA571 has been linked to delivery of Ursnif, ZLoader, DanaBot, IcedID, Rhadamanthys, DarkGate, NetSupport RAT, Matanbuchus, and other payloads, and its activity has repeatedly been assessed as capable of leading to ransomware deployment even when TA571 is not the final-stage operator. The actor commonly uses email-based initial access at scale, including thread hijacking, malicious hyperlinks, HTML attachments, password-protected archives, and links routed through traffic distribution infrastructure. TA571 has used compromised, spoofed, and legitimate hosting services for payload delivery and has employed gated delivery chains with filtering and geo-fencing to restrict access to intended victims and reduce sandbox visibility. It has also been associated with social-engineering innovations such as ClickFix, in which victims are tricked into copying and executing malicious PowerShell commands from fake error or application-fix prompts. TA571 was among the earliest prominent adopters of this technique in 2024, using lures themed around Microsoft Word, OneDrive, browser errors, and certificate warnings. TA571 has delivered both traditional banking-malware-derived loaders and modern stealers or remote access payloads. Observed campaigns include delivery of the Forked variant of IcedID via thread-hijacked emails and 404TDS redirect chains, Rhadamanthys in campaigns later linked to TA866 post-compromise activity, and ClickFix-based chains leading to DarkGate, Matanbuchus, and NetSupport RAT. Reporting also characterizes TA571 as an affiliate or partner within a broader cybercrime ecosystem, including affiliation with infrastructure or services tied to 404TDS and relationships with other actors responsible for later-stage exploitation. Operationally, TA571 fits the profile of an access-enabling actor rather than a full-spectrum intrusion group in every case. It is frequently described as obtaining footholds and distributing malware on behalf of cybercriminal customers, with follow-on activity sometimes attributed to separate actors. This role, combined with its scale, adaptability, and repeated use of evasive delivery mechanisms, makes TA571 a significant enabler of financially motivated intrusions across multiple sectors worldwide.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
40 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor associated (in related reporting) with ClearFake-style social engineering used to deliver PowerShell-based malware via fake CAPTCHA/ClickFix lures.
Priority cybercriminal threat actor that distributed Rhadamanthys in campaigns beginning in December 2022 and has used both exclusive and broadly available malware.
TA571 is involved in phishing campaigns using fake Google Meet pages to deliver malware such as AsyncRAT, StealC, and Rhadamanthys, targeting both Windows and macOS users.
Cybercriminal group observed distributing DanaBot in email campaigns between 2018 and 2020.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.