TA569 is a financially motivated cybercriminal threat actor associated with SocGholish campaigns. Active since at least 2018, the actor is primarily focused on initial access and monetization of compromised systems rather than operating as the downstream ransomware actor itself. TA569 uses injected JavaScript on compromised legitimate websites to present fake browser update prompts that deliver SocGholish, relying heavily on trusted web properties, legitimate marketing channels, and SEO-driven traffic instead of traditional phishing lures. TA569’s operations are characterized by sophisticated victim filtering, eligibility checks, and obfuscation designed to complicate prevention, analysis, and incident response. After execution, SocGholish performs host profiling, including use of Windows Management Instrumentation, and exfiltrates basic system and domain context to support follow-on decisions. Infections on domain-joined enterprise systems have been linked to rapid follow-on deployment of ransomware families including WastedLocker, Hive, and LockBit, while non-domain-joined systems have been used for remote access trojan deployment and credential harvesting. Reporting has noted overlap in post-compromise activity with actors such as EvilCorp, Gold Drake, and UNC2165, but TA569 is best understood as the access-focused operator managing SocGholish delivery and victim qualification. The actor’s campaigns have affected users across multiple countries and pose a persistent enterprise threat because they abuse legitimate websites and social engineering around software updates, enabling low-dwell-time compromises and efficient handoff to additional malware or ransomware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.