TA505 — Ransomware Profile
TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.Also tracked as
Hive0065, Spandex Tempest, CHIMBORAZO, Lace Tempest, FIN11 overlap
Tools & malware
- AdFind Network Reconnaissance
- Amadey Loader
- Azorult Infostealer
- BloodHound Network Reconnaissance
- Clop Ransomware
- Cobalt Strike Adversary Simulation
- Dridex Banking Trojan
- FlawedAmmyy Remote Access Trojan
- FlawedGrace Remote Access Trojan
- Get2 Downloader
- Mimikatz Credential Harvesting
- Net Network Reconnaissance
- PowerSploit Post-Exploitation Framework
- SDBbot Remote Access Trojan
- ServHelper Backdoor
- TrickBot Banking Trojan
Vendor research
- Profiling of TA505 Threat Group That Continues to Attack the Financial Sector Financial Security Institute
- TA505 Continues to Infect Networks With SDBbot RAT Frydrych, M
- How Microsoft names threat actors Microsoft
- TA505 shifts with the times Proofpoint
- Profiling of TA505 Threat Group That Continues to Attack the Financial Sector Korean FSI
- TA505: A Brief History of Their Time NCC Group
- ServHelper and FlawedGrace - New malware introduced by TA505 Proofpoint
- TA505 Continues to Infect Networks With SDBbot RAT IBM
- Threat Actor Profile: TA505, From Dridex to GlobeImposter Proofpoint