TA800 is a financially motivated cybercrime threat actor and initial-access facilitator active since at least 2019. The group is best known for large-scale email-driven malware delivery operations using social engineering to install banking malware and loaders, including The Trick (Trickbot), BazaLoader, Buer Loader, Ostap, and later NimzaLoader. TA800 is widely associated with affiliate-style criminal distribution activity rather than a single proprietary malware family. TA800 has targeted multiple industries in North America, with especially notable activity against the healthcare sector. The actor has conducted phishing campaigns using personalized lures, fake document-preview themes, and links to staged download pages to induce victims to retrieve malware. In campaigns involving NimzaLoader, TA800 used phishing emails containing recipient- or company-specific details and fake PDF-preview links leading to malware downloads. NimzaLoader is a distinct loader written in Nim and has been observed using encrypted strings, JSON-based command-and-control communications, HTTPS transport, command execution through cmd.exe and PowerShell, heartbeat-style configuration updates, and shellcode injection into processes. NimzaLoader has also been reported as a precursor to Cobalt Strike deployment. TA800 has predominantly used BazaLoader in campaigns from 2020 onward and is assessed with high confidence to be related to BazaLoader activity that enabled Ryuk ransomware intrusions. More broadly, TA800 payload chains have been observed distributing ransomware, and the actor is associated with the criminal ecosystem in which loader infections are monetized through follow-on access, post-exploitation tooling, and ransomware deployment by affiliates or partners. TA800 therefore fits the profile of a major malware distributor and ransomware-enablement actor within the broader cybercrime landscape.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access facilitator delivering banking malware and loaders that have been used to enable ransomware deployment, including links to Ryuk distribution via BazaLoader implants.
Uses NimzaLoader as an initial access and foothold tool in enterprise compromises, distributing it through personalized phishing emails and commonly deploying Cobalt Strike as a second-stage payload.
Conducting email-based initial access campaigns using personalized lures and links to deliver NimzaLoader; previously associated with BazaLoader, Buer Loader, and Trick, with evidence suggesting secondary delivery of Cobalt Strike.
Affiliate distributor delivering Trickbot ('The Trick') and BazaLoader via malspam/phishing; in Q4 linked to healthcare-focused campaigns where BazaLoader led to Ryuk ransomware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.