TA578 is a financially motivated ecrime threat actor and likely initial access broker tracked since 2020. The actor is best known for large-scale malware delivery operations that rely on social engineering, especially abuse of website contact forms and email-based lures themed around copyright complaints, stolen images, invoices, and related business pretexts. TA578 has consistently targeted organizations globally and is closely associated with botnet and loader ecosystems rather than a single proprietary malware family. TA578 has delivered a wide range of malware over time, including Ursnif, IcedID, KPOT Stealer, Buer Loader, BazaLoader, Bumblebee, DanaBot, SSLoad, Latrodectus, and Cobalt Strike. Since mid-January 2024, TA578 has been a primary distributor of Latrodectus in observed campaigns, including chains in which contact-form messages direct victims to personalized landing pages that deliver JavaScript and MSI-based installers. The actor has also been observed delivering DanaBot, including a campaign in which DanaBot dropped Latrodectus, and has longstanding associations with Standard IcedID distribution and later Bumblebee operations. Operationally, TA578 commonly initiates victim engagement through public website contact forms, often impersonating companies or legal representatives and alleging copyright infringement or misuse of images. The actor has placed malicious links in those submissions to redirect targets to malware-hosting pages. TA578 has repeatedly used JavaScript in execution chains and has hosted malicious scripts on trusted web infrastructure such as Google Firebase. Observed delivery chains have included JavaScript, MSI installers, WebDAV-hosted payload retrieval, ISO and LNK-based execution, and follow-on loader activity that enables additional payload deployment. TA578 is widely assessed as part of the cybercrime ecosystem supporting downstream intrusion activity by delivering initial malware footholds and loaders that can enable further compromise. Its tradecraft emphasizes scalable initial access, malware staging, and payload handoff rather than public extortion branding. The actor is also associated with thematic clustering in historic IcedID campaigns, including automobile-themed campaign identifiers, which has helped distinguish its activity from other IcedID distributors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
80 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the MMC/GrimResource detection analytic.
Listed in annotations as a threat actor associated with the detection context; no specific activity beyond inclusion in the analytic metadata is described.
Listed as a threat actor associated with malicious link execution and spearphishing attachment activity relevant to ISO/LNK delivery detection.
Uses Latrodectus in phishing campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.