TA578 — Ransomware Profile

TA578 is a financially motivated cybercriminal cluster that Proofpoint has tracked since May 2020, distributing malware through email and by submitting fake copyright-infringement complaints via the contact forms on targeted organisations' own websites. Its payloads have included Ursnif, KPOT Stealer, Buer Loader, BazaLoader, Cobalt Strike, IcedID and Bumblebee, and since December 2023 it has used the Latrodectus loader almost exclusively. TA578 is an access-enabling distributor rather than a ransomware operator in its own right — it runs no encryptor and no leak site — but Proofpoint assesses with high confidence that Bumblebee acts as an initial-access facilitator for follow-on ransomware, and Kroll traced Bumblebee infections into Quantum Locker deployments. No vendor has attributed TA578 to a country; Proofpoint noted that its Bumblebee campaigns overlap with the EXOTIC LILY activity reported by Google, but neither vendor equates the two clusters.

Tools & malware

Vendor research

Read the full analysis on IntelFusions