TA516 is a financially motivated cyber threat actor known for large-scale malicious email campaigns that use employment-themed social engineering lures and password-protected documents to deliver malware. The actor has been associated with campaigns that require victims to open protected documents and enable macros, after which an information-stealing downloader is installed. In observed operations, the malware collected credentials, browser cookies, system information, and cryptocurrency wallet data, then retrieved additional payloads including Hermes 2.1 ransomware. This combination of credential and cryptocurrency theft with follow-on ransomware deployment enabled both data theft and disruptive file encryption in a single intrusion chain. TA516 has also been linked to earlier activity involving resume-themed lures used to distribute banking Trojans and cryptocurrency-mining malware, indicating sustained interest in financially oriented malware delivery and cryptocurrency-related theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.