TA582 is a post-exploitation and initial-access operator also tracked as UNC4108. It operates downstream of SocGholish/FakeUpdates and TAG-124 traffic-distribution-system infection chains that use compromised websites, fraudulent browser-update lures, or ClickFix-style social engineering to obtain access to Windows systems. TA582 has been associated with GhostWeaver, a fileless PowerShell remote-access trojan, and has also deployed AsyncRAT or BOINC RAT against selected hosts. Its operations include host, Active Directory, network, account, session, and administrative-share discovery; browser credential and encryption-key theft; NTLM-hash theft; and collection of local credential material. Observed tradecraft includes PowerShell obfuscation, process injection, DLL sideloading preparation, scheduled-task persistence, reverse SSH or proxy-based access, Outlook-signature modification intended to capture or relay NetNTLM authentication, and removal of staged data and reconnaissance artifacts. GhostWeaver uses in-memory PowerShell execution, anti-analysis profiling through MintsLoader, dynamically generated infrastructure, AV-aware persistence selection, scheduled tasks, and a CMSTPLUA-based UAC bypass. TA582 has been identified as one of several downstream customers of TAG-124 and is distinct from the operators of the shared access-delivery infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an APT customer of KongTuke's infection distribution service.
Operator attributed to the GhostWeaver fileless PowerShell RAT activity, delivered downstream of the SocGholish fake browser update infection chain; uses sandbox-aware delivery (MintsLoader profiling), AV-aware persistence selection, fileless in-memory execution, DGA-based C2 with direct queries to public DNS resolvers, and TLS C2 on a non-standard port.
Post-exploitation operator within the TAG-124 TDS ecosystem. Runs downstream activity after initial access, including MintsLoader victim scoring/profiling, DGA infrastructure, GhostWeaver (Pantera) deployment, and delivery of a PowerShell persistence installer; uses sandbox evasion to deliver decoys to analysis environments and real payloads to low-score (real) machines.
A named activity cluster assessed to leverage TAG-124 as a delivery component in initial infection chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.