TA505 is a prolific financially motivated cybercrime threat actor best known for operating some of the largest malicious spam campaigns observed in the email threat landscape. The group has been associated with high-volume malware distribution operations since at least 2014 and is widely linked to the delivery of banking trojans, downloaders, credential-stealing malware, and ransomware. TA505 is also associated with the subgroup FIN11, which has been tied to ransomware and extortion activity since at least 2020. TA505 has distributed malware including Dridex, Locky, Jaff, TrickBot, Shifu, Bart, Rockloader, Kegotip, Pony, Andromeda, Philadelphia, and GlobeImposter. Its operations have shown repeated shifts in payloads and delivery chains, including the use of intermediate loaders and affiliate-style distribution models. Several malware families, including Jaff, Bart, and Rockloader, have been described as closely associated with the group. The actor is particularly notable for massive email-based initial access activity, often sending campaigns at very large scale through compromised infrastructure and botnet-supported spam delivery. TA505 has been linked to use of the Necurs botnet to amplify malicious email operations, and disruptions affecting Necurs have historically coincided with temporary reductions in TA505 activity followed by rapid resurgence. Delivery methods have included macro-enabled Office documents, PDFs embedding malicious documents, JavaScript, VBScript, HTML attachments, password-protected documents, and malicious links. In some campaigns, macros invoked PowerShell to install follow-on malware. TA505’s activity has included distribution of banking malware and credential theft tooling, as well as ransomware operations. Dridex and TrickBot were used in banking-trojan campaigns, while Kegotip was used to steal credentials and harvest email addresses. The group played a major role in the spread of Locky ransomware and later distributed Jaff and Bart. FIN11, identified as a subset of TA505, has additionally been associated with ransomware and extortion operations. More recent reporting has linked a high-volume extortion email cluster to compromised accounts previously associated with FIN11, although direct attribution of that cluster to another branded ransomware operation has not been confirmed. TA505 demonstrates strong adaptability in payload selection, delivery technique, and campaign scale. Its core strengths are high-volume initial access via email, malware delivery, credential theft, and broad post-compromise monetization in support of financially motivated cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TA505 is a larger threat actor group known for financially motivated cybercrime, including ransomware and extortion, with sub-groups such as FIN11 conducting specific operations.
TA505 is a financially motivated cybercrime group known for operating massive global spam campaigns to distribute a wide variety of malware, including banking trojans and ransomware. They are highly adaptable, frequently shifting malware payloads and techniques, and are deeply connected to the cybercrime underground. Their operations have driven global trends in malware distribution and email-based threats.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.