TA2101 is a financially motivated cybercrime threat actor tracked for malspam campaigns in late 2019 that targeted organizations in Germany, Italy, and the United States. The actor is notable for using convincing email impersonation of government agencies and trusted brands, including tax authorities and postal or internet service themes, to induce recipients to open malicious Microsoft Word attachments and enable macros. Those macros launched PowerShell to retrieve and install follow-on payloads. TA2101 has been observed delivering multiple malware families depending on campaign and target region, including Maze ransomware, Cobalt Strike, and the IcedID banking Trojan. German and Italian campaigns were associated primarily with Maze ransomware delivery, while a U.S. campaign delivered IcedID and at least one German campaign delivered Cobalt Strike, indicating operational flexibility in payload selection. Proofpoint attributed these campaigns to a single actor with high confidence based on consistent infrastructure and tradecraft patterns. The actor’s social-engineering tradecraft includes spoofing government tax agencies, using stolen branding, and registering lookalike domains to increase lure credibility. Observed targeting included primarily IT services companies in Germany, manufacturing companies in Italy, and heavy targeting of the healthcare sector in the United States. TA2101 has also been identified as a Maze affiliate in reporting on Maze ransomware operations, linking the actor to ransomware intrusion activity and associated extortion operations conducted under the Maze ecosystem. TA2101 should be understood as a cybercriminal actor associated with phishing-led initial access and malware delivery rather than a confirmed nation-state group. Claims in some reporting that attempt to connect TA2101 to Russian state-linked actors were presented only as analytical suspicion and are not established attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only as a source/reference, not discussed as part of the event itself.
Described as actively using Maze ransomware in campaigns targeting organizations in Germany, Italy, and the United States via malicious email delivery.
An identified affiliate associated with Maze-linked activity, known for malspam campaigns impersonating government agencies; referenced as a potential actor to impersonate Allied Universal in spam using stolen certificates.
Conducted email-based malware delivery campaigns in Germany, Italy, and the United States using government and brand impersonation lures to distribute Cobalt Strike, Maze, and IcedID.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.