🇷🇺TA505
🇷🇺 TA505 is a tracked threat actor in the Clankerusecase corpus. RU-aligned. Primary motivation: Criminal. We map 14 detection use cases to this actor across 34 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.
14Use cases
0Articles
34Techniques
0IOCs
About this actor (MITRE)
[TA505](https://attack.mitre.org/groups/G0092) is a cyber criminal group that has been active since at least 2014. [TA505](https://attack.mitre.org/groups/G0092) is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving [Clop](https://attack.mitre.org/software/S0611).(Citation: Proofpoint TA505 Sep 2017)(Citation: Proofpoint TA505 June 2018)(Citation: Proofpoint TA505 Jan 2019)(Citation: NCC Group TA505)(Citation: Korean FSI TA505 2020)
Known aliases
TA505Hive0065Spandex TempestCHIMBORAZO
Top techniques
All other tracked techniques
T1055.001 · Dynamic-link Library InjectionT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1069 · Permission Groups DiscoveryT1071.001 · Web ProtocolsT1078.002 · Domain AccountsT1087.003 · Email AccountT1105 · Ingress Tool TransferT1106 · Native APIT1112 · Modify RegistryT1140 · Deobfuscate/Decode Files or InformationT1204.001 · Malicious LinkT1204.002 · Malicious FileT1218.007 · MsiexecT1218.011 · Rundll32T1486 · Data Encrypted for ImpactT1552.001 · Credentials In FilesT1553.002 · Code SigningT1553.005 · Mark-of-the-Web BypassT1555.003 · Credentials from Web BrowsersT1559.002 · Dynamic Data ExchangeT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1568.001 · Fast Flux DNST1583.001 · DomainsT1588.001 · MalwareT1588.002 · ToolT1608.001 · Upload MalwareT1685 · Disable or Modify Tools