TA551, also known as Shathak, is a financially motivated cybercriminal spam-distribution actor best known for large-scale malspam campaigns that deliver banking malware, information stealers, loaders, and remote-access tooling. The actor has been closely associated with the distribution of Ursnif and later Valak, with Valak becoming a prominent payload in 2020. TA551 commonly uses email-based initial access with password-protected archive attachments containing malicious Microsoft Word documents that rely on user-enabled macros to retrieve and execute additional malware. The actor has also spoofed legitimate email threads using information harvested from previously compromised systems, increasing delivery credibility and click-through rates. Operationally, TA551 functions as a malware delivery network rather than being defined by a single malware family. Campaigns attributed to the actor have used staged infection chains in which delivered malware establishes persistence, retrieves follow-on payloads, and supports credential theft and data exfiltration. In Valak-related activity, infections have used scheduled tasks and registry-based persistence, obfuscated scripts and configuration data for defense evasion, and Alternate Data Streams to conceal and launch follow-up malware. TA551 campaigns have targeted recipients across multiple language groups, including English, Italian, German, and Japanese-speaking users, indicating broad international victimization rather than a narrowly regional focus. The actor is widely tracked in the cybercrime ecosystem for reliable initial access and malware distribution tradecraft, especially through socially engineered email lures and attachment-based execution chains. Available reporting also notes possible association with Russian cybercriminal activity, but attribution to a specific state sponsor is not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.