TA571 is a financially motivated cybercriminal initial-access group and high-volume spam distributor active since at least 2019. It operates or is associated with spam-botnet and 404TDS traffic-distribution infrastructure, delivering malware for downstream criminal customers rather than being identified as a ransomware operator itself. TA571 has distributed banking malware, loaders, remote-access tools, and information stealers including Ursnif, ZLoader, DanaBot, IcedID, DarkGate, Matanbuchus, NetSupport RAT, Rhadamanthys, and malware associated with TA866/Asylum Ambuscade. Its campaigns commonly use malspam, compromised or spoofed infrastructure, file-hosting services, HTML attachments, malicious links, password-protected archives, and email-thread hijacking. In 2023, TA571 distributed the Forked IcedID variant through gated 404TDS delivery chains; the variant's reduced banking functionality was consistent with use as a payload-delivery mechanism. In 2024, TA571 was among the earliest documented users of ClickFix, using large-scale email campaigns and fake Word or OneDrive-themed error prompts to induce recipients to paste and execute attacker-supplied PowerShell commands. TA571 employs traffic filtering and geo-fencing gates to restrict payload delivery and impede analysis. Its initial-access operations have been assessed as capable of leading to ransomware deployment by downstream actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
40 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as historical background for early ClickFix campaign usage; it is not connected to the StopAndProtect operation described.
Referenced as a threat actor associated (in related reporting) with ClearFake-style social engineering used to deliver PowerShell-based malware via fake CAPTCHA/ClickFix lures.
Priority cybercriminal threat actor that distributed Rhadamanthys in campaigns beginning in December 2022 and has used both exclusive and broadly available malware.
TA571 is involved in phishing campaigns using fake Google Meet pages to deliver malware such as AsyncRAT, StealC, and Rhadamanthys, targeting both Windows and macOS users.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.