TA581 is a financially motivated cybercrime threat actor tracked since mid-2022 and formally designated in 2023. It is assessed to function primarily as an initial access facilitator or malware distributor rather than a full-spectrum intrusion group with a uniquely distinctive operational profile. Reporting links TA581 to distribution of the Forked variant of IcedID, a modified IcedID codebase that deemphasizes traditional banking-trojan functionality in favor of loader behavior for follow-on payload delivery. Observed TA581 campaigns in early 2023 used high-volume email delivery with social-engineering themes such as invoices, product recalls, and regulatory lures. Delivery chains included Microsoft OneNote and URL attachments that ultimately executed scripts or command interpreters and launched malware through rundll32 using non-standard exports. The actor’s activity aligns with initial-access tradecraft centered on malicious email, attachment-based execution, and staged loader deployment. TA581 has been associated specifically with the Forked IcedID variant rather than the long-standing Standard variant. The Forked branch preserves loader-style command-and-control behavior while supporting downstream payload delivery, consistent with criminal access operations that monetize footholds by enabling later-stage malware deployment. Available evidence also indicates TA581 campaign identifiers lacked strongly unique patterns, reinforcing the assessment that the actor may overlap with other distribution clusters or operate chiefly as a delivery specialist within a broader cybercrime ecosystem. Known aliases are limited to TA581.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an IcedID-associated activity cluster; lack of unique campaign-ID patterns suggests it may be primarily a distributor or overlapping with another group. No additional operational details provided in this content.
Threat actor referenced in the IcedID campaign-ID attribution analysis; suspected to be primarily a distributor or to overlap with another threat group.
Initial access facilitator distributing the Forked IcedID variant (and sometimes Bumblebee/TOAD), using business-themed lures and varied attachment types; linked to large-scale email campaigns delivering IcedID via OneNote/HTA/PowerShell chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.