TA577
TA577 is a prolific Russia-based cybercrime threat actor and initial access broker tracked by Proofpoint since mid-2020. The group conducts broad phishing campaigns across multiple industries and geographies and has been observed delivering payloads including Qbot/Qakbot, IcedID, SystemBC, SmokeLoader, Ursnif, Cobalt Strike, and more recently Pikabot, DarkGate, and Latrodectus. Proofpoint has described TA577 as a prolific Qbot distributor prior to Qbot’s 2023 disruption, and TA577 activity has previously been observed leading to ransomware, including Black Basta; Proofpoint also assessed with high confidence that TA577 was associated with a March 2021 Sodinokibi infection initiated through malicious Office attachments that downloaded IcedID. Reported aliases in the content include Water Curupira, and one mention notes likely overlap or confusion with TA551 (Shathak), but this is not established as a confirmed alias. Observed delivery and execution tradecraft includes phishing, thread hijacking, HTML files that trigger outbound SMB connections to file:// URLs to capture NTLMv2 handshakes, BAT files in malware execution chains, JavaScript-based execution, LNK files used to execute embedded DLLs, and a JAR dropper that wrote a disguised DLL to %TEMP% and launched it with regsvr32.exe to deliver Pikabot. TA577 also distributed Latrodectus in phishing campaigns beginning in November 2023 and used it in at least three campaigns before reverting to Pikabot. Proofpoint reported that TA577 activity decreased or disappeared from email campaign data since mid-2024, likely in the broader disruption context affecting multiple initial access broker ecosystems.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
Observables
106 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with Windows Command Shell execution behavior relevant to this detection.
Listed as a threat actor associated with the MMC/GrimResource detection analytic.
Likely delivery operator for this campaign, using KongTuke traffic distribution to deliver a signed MSI that drops IcedID, which then leads to Latrodectus C2 activity. The report frames this as a ransomware-precursor and credential-theft intrusion chain.
Listed as a threat actor associated with the named-pipe impersonation privilege-escalation detection.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.