TA574 is a cybercrime threat actor focused on large-scale email-based malware distribution. It is tracked as a prolific distributor associated with broad, cross-industry phishing activity and is known for delivering ZLoader through socially engineered email campaigns. The actor has used high-volume lures themed around tax and financial matters, including impersonation of tax authorities and financial representatives, to induce recipients to open malicious spreadsheet attachments and enable macros. TA574’s operations are characterized by opportunistic targeting at scale rather than narrow victim specialization. Reported activity includes campaigns sending tens of thousands of messages and targeting organizations across multiple sectors. The actor commonly relies on malicious Office documents, especially Excel files with macros, as an initial infection vector. Observed tradecraft also includes geotargeting and user-agent checks prior to malware delivery, indicating efforts to tailor payload deployment and reduce exposure to automated analysis or unwanted regions. TA574 has been described as part of the broader criminal ecosystem of malware distributors and initial-access facilitators that deliver first-stage payloads later used for follow-on intrusion activity. In this role, the actor’s primary function is to establish footholds or deliver banking trojan and loader malware rather than to conduct final-stage ransomware deployment directly. ZLoader, one of the malware families associated with TA574, has been linked in wider criminal operations to credential theft, financial fraud, and downstream access monetization. TA574 is best understood as a financially motivated spam and malware delivery actor operating within the cybercrime affiliate landscape. No high-confidence attribution to a nation state is supported.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
High-volume actor conducting broad industry targeting with malicious Office attachments and pre-delivery filtering such as geotargeting and user-agent detection.
Large-scale indiscriminate cybercrime campaigns using IRS-themed phishing emails and macro-enabled Excel documents to install banking malware.
Newer affiliate/distributor observed delivering Zloader (Zeus offshoot) and Ostap; noted for using a JavaScript-based downloader to evade sandbox analysis.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.