TA577 is a prolific financially motivated cybercrime threat actor and initial access broker active since at least 2020. The group is widely associated with large-scale phishing and malspam operations that deliver a rotating set of commodity and modular malware families, including QakBot, IcedID, SystemBC, SmokeLoader, Ursnif, Cobalt Strike, PikaBot, DarkGate, and Latrodectus. TA577 has been described as Russia-based. TA577 typically conducts broad, opportunistic targeting across industries and geographies rather than focusing on a single vertical. Its operations have affected organizations globally, including victims in North America and Europe. The actor is notable for repeatedly adapting delivery mechanisms to changing defensive conditions, including use of malicious Office documents, OneNote attachments, ZIP archives, HTML smuggling-style lures, LNK files, JavaScript, HTA, and batch-script-based execution chains. Observed campaigns have included thread hijacking and conversation hijacking to improve phishing credibility. The actor is strongly associated with email-borne initial access and malware delivery. Reported tradecraft includes OneNote-based delivery chains for QakBot, JavaScript-based downloaders, BAT-file execution chains, and LNK files used to execute embedded DLL payloads. TA577 has also distributed malware through customized HTML attachments designed to trigger outbound SMB authentication and capture NTLM challenge-response material, indicating an expansion from straightforward payload delivery into credential-access operations. Follow-on activity linked to TA577-delivered access has included ransomware ecosystems such as Black Basta, and reporting has assessed the actor as an initial access broker that facilitates later-stage intrusions. TA577 has shown overlap with broader cybercrime delivery ecosystems involving IcedID, QakBot, PikaBot, DarkGate, and Latrodectus. Its campaigns commonly emphasize defense evasion and flexible staging, using signed or trusted Windows utilities, embedded objects, and multi-stage loaders to retrieve and execute additional malware. The actor’s role in the intrusion chain is primarily to obtain footholds and deliver payloads that enable downstream post-exploitation, credential theft, lateral movement, and ransomware deployment by partners or affiliates.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
251 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of the threat actors using the DarkGate MaaS loader/RAT.
Referenced as using OneNote documents to deliver Qakbot in late January 2023 as part of broader malware distribution activity.
Listed as a threat actor associated with the MMC/GrimResource detection analytic.
Listed as a threat actor associated with Windows Command Shell execution behavior relevant to this detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.