TA577, also tracked as Hive0118, is a prolific global email-based malware distributor and initial-access actor closely associated with campaigns that enable downstream ransomware operations. The actor is linked in reporting to the Trickbot/Conti-aligned ITG23 ecosystem and is known for delivering commodity and enterprise-focused malware loaders that frequently precede hands-on intrusion activity and ransomware deployment. TA577 commonly conducts large-scale phishing operations using stolen emails and thread hijacking to increase message credibility and improve victim interaction rates. Its campaigns have delivered malware families including DarkGate, QakBot, IcedID, and PikaBot, and it has used crypters associated with the ITG23 ecosystem, including Forest, Snow, and Quicksand, as well as Dave-crypted PikaBot in observed 2024 activity. The actor’s role is primarily initial access: distributing payloads that establish footholds later leveraged by other operators, including ransomware affiliates. Observed tradecraft includes malicious email attachments and links, staged script downloaders, and delivery chains that retrieve and execute subsequent payloads. TA577’s operations are notable for broad geographic reach rather than narrowly scoped regional targeting. PikaBot infections delivered by this actor have frequently been associated with later Black Basta ransomware activity, reinforcing TA577’s significance as an upstream access provider in financially motivated intrusion chains.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Email distributor / initial access cluster using thread hijacking and stolen email conversations to deliver loaders (including PikaBot, DarkGate, Qakbot, IcedID), often serving as an access broker for ransomware operators associated with the Trickbot/Conti ecosystem.
Referenced as a malware distributor known for leveraging stolen email threads (thread hijacking) to improve phishing success.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.