TA577 is a prolific cybercrime threat actor and initial access broker active since at least 2020. The group is assessed to be Russia-based and is best known for large-scale phishing campaigns that broadly target organizations across industries and geographies. TA577 has repeatedly delivered commodity and modular malware associated with follow-on intrusion activity, including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, Cobalt Strike, and, more recently, Pikabot, DarkGate, and Latrodectus. The actor has also been linked to intrusion chains that later resulted in ransomware deployment, including observed associations with Sodinokibi and Black Basta, making TA577 activity a significant ransomware-precursor threat. TA577 commonly operates as an access-enablement actor rather than a final-stage extortion crew. Its tradecraft centers on phishing-based initial access and malware delivery, including thread-hijacking email campaigns and broad malspam operations. Observed execution chains have used JavaScript, batch files, Windows command shell activity, Java Archive droppers, and LNK files that execute embedded DLLs. The actor has delivered malware through attachment- and script-based infection chains and has shown flexibility in experimenting with new loaders and delivery formats, including JAR-based Pikabot delivery and campaigns involving HTML files that triggered outbound SMB authentication to capture NTLMv2 handshakes. TA577 has been strongly associated with the distribution ecosystem around Qbot and IcedID and later with Pikabot and Latrodectus after disruptions affected earlier malware infrastructure. The group’s operations reflect the broader cybercrime division of labor in which initial access brokers distribute first-stage malware that is later monetized through access sales or follow-on deployment by other criminal operators. An alias observed for TA577 is Water Curupira.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
106 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with Windows Command Shell execution behavior relevant to this detection.
Listed as a threat actor associated with the MMC/GrimResource detection analytic.
Likely delivery operator for this campaign, using KongTuke traffic distribution to deliver a signed MSI that drops IcedID, which then leads to Latrodectus C2 activity. The report frames this as a ransomware-precursor and credential-theft intrusion chain.
Listed as a threat actor associated with the named-pipe impersonation privilege-escalation detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.