TA543, also known as Sagrid, is a financially motivated cybercriminal threat actor tracked by Proofpoint. It conducts high-volume malicious email campaigns with widespread, opportunistic targeting, typically sending thousands of messages to hundreds of organizations. Targeted sectors include finance, manufacturing, technology, retail, healthcare, education, and transportation. Its activity includes Ursnif campaigns against Australian users and malware distribution that enables downstream ransomware attacks. TA543 commonly uses invoice, billing-notification, and package-delivery lures, impersonating recognizable software and logistics brands. Delivery mechanisms include malicious Microsoft Office documents and links routed through traffic distribution systems such as BlackTDS and Keitaro. Infection chains have used SharePoint-hosted VBScript and Windows Script Files, sometimes with intermediate downloaders, to install JSSLoader. A historical campaign also used a compromised email-marketing service account to distribute malicious messages. TA543 has been a prominent distributor of JSSLoader, an initial-access loader that profiles infected systems, communicates with command-and-control infrastructure, establishes persistence, and executes additional payloads. Its campaigns have distributed both the original .NET implementation and a C++ rewrite observed in June 2021. TA543-delivered JSSLoader has loaded Griffon, a payload associated with FIN7. These operational relationships connect TA543 to the broader criminal access-distribution and ransomware ecosystem without establishing that it is the same actor as FIN7.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a recipient of compromised-system access from Storm-0324 that uses the supplied access to carry out ransomware attacks. The report provides no further actor-specific technical details.
Financially motivated threat actor tracked by Microsoft as a Storm cluster.
Spam distribution actor hired by the RM3/Global Network group to send malicious spam for malware delivery.
Conducting large-scale email campaigns delivering JSSLoader via invoice and package-delivery themed lures, using TDS landing pages and script-based download chains to infect a wide range of organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.