TA551, also known as Shathak, GOLD CABIN, MARIO KART, MONSTER LIBRA, and DEV-0365, is a financially motivated cybercriminal threat group focused on phishing-based malware delivery and initial-access brokerage. Its operations have delivered IcedID and WikiLoader and have supplied initial access for Conti ransomware affiliates. This relationship does not establish TA551 as the operator of the subsequent ransomware deployments. TA551 uses hijacked email conversations and spearphishing attachments, including password-protected ZIP archives and malicious Microsoft Office documents. Its document-based infection chains persuade recipients to enable macros that download and execute malware. Campaigns have used COVID-19-themed lures against English-speaking victims. In March 2023, TA551 targeted Italian organizations with OneNote attachments containing embedded executable content that downloaded and launched WikiLoader. Its execution techniques include Windows command-shell commands and abuse of legitimate Windows utilities for system binary proxy execution, including the Microsoft HTML Application Host and Windows registration utility. Defense-evasion techniques include disguising malicious DLLs as data or image files and obfuscating JavaScript configuration variables. TA551 retrieves DLLs and installer binaries from command-and-control infrastructure, uses HTTP communications, and has encoded initial command-and-control messages as ASCII text. IcedID infection chains delivered through its campaigns incorporate credential theft, scheduled-task persistence, encrypted payloads concealed in images, process injection, and anti-analysis checks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
Kevin Beaumont reported on this conversation hijacking technique back in November 2021 being used to distribute Qakbot. Through the investigation, he confirmed that the Microsoft Exchange servers where the emails originated from had evidence of being exploited by ProxyShell... The majority of the originating Exchange servers we have observed appear to also be unpatched and publicly exposed, making the ProxyShell vector a good theory.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
252 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the detection annotation metadata.
Referenced only as an annotated actor associated with the detection technique.
Listed only in the detection's ATT&CK/actor annotations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.