TA543 is a financially motivated cybercrime threat actor primarily known for large-scale malspam operations and malware delivery. The group has been associated with widespread, opportunistic email campaigns that distribute banking trojans and loaders, especially Ursnif and JSSLoader, using invoice, billing, and package-delivery themed lures with spoofed commercial branding. Campaigns are characterized by high message volume, broad sector coverage, and targeting of hundreds of organizations at a time rather than narrowly focused victim selection. TA543 has been linked to delivery activity within the broader ISFB/Ursnif ecosystem. Reporting connects the actor to spam distribution in support of criminal malware operations and places it among groups used to send large phishing waves for downstream payload delivery. In observed campaigns, TA543 used malicious Office documents and multi-stage download chains to establish initial access, after which malware performed host profiling, persistence, command-and-control communications, and retrieval of additional payloads. JSSLoader activity attributed to TA543 included a transition from a .NET implementation to a C++ rewrite while preserving core loader functionality, likely to improve evasion and complicate analysis. Observed TA543 operations have targeted organizations across finance, manufacturing, technology, retail, healthcare, education, and transportation, and have also included geographically specific Ursnif campaigns against users in Australia. The actor’s tradecraft supports initial compromise and follow-on malware deployment, with capabilities aligned to credential theft and broader post-compromise enablement through loader activity. Microsoft maps TA543 to the financially motivated cluster Storm-0324. An alias associated with the actor is Sagrid.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated threat actor tracked by Microsoft as a Storm cluster.
Spam distribution actor hired by the RM3/Global Network group to send malicious spam for malware delivery.
Conducting large-scale email campaigns delivering JSSLoader via invoice and package-delivery themed lures, using TDS landing pages and script-based download chains to infect a wide range of organizations.
Targeted Ursnif campaign against Australian users using malicious Microsoft Word documents and a billing-notification lure leveraging stolen branding from a New Zealand-based accounting software company.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.