TA554 is a financially motivated cybercrime threat actor active since at least 2017 and known for large-scale phishing campaigns that deliver banking malware. The actor has been closely associated with the PowerShell downloader sLoad, which it used from at least 2018 to stage and deliver payloads including Ramnit, Gootkit, Ursnif, PsiXBot, and DarkVNC. TA554 commonly uses localized and personalized malspam themed around package delivery or order notifications, often directing victims to ZIP archives containing malicious shortcut files or documents that launch obfuscated PowerShell. The actor has also adapted its delivery chains over time, including simplifying stages so victim-facing shortcut files retrieve sLoad directly. TA554’s operations emphasize stealth, filtering, and post-delivery triage. Campaigns have used geofencing at multiple stages to restrict payload delivery by victim location, and some stages have included checks intended to ensure requests originate from expected Windows components. sLoad supports extensive host reconnaissance, including process enumeration, operating system and hardware profiling, network and domain context collection, checks for Outlook and Citrix-related artifacts, DNS-cache inspection for banking-related targets, screenshot capture, and reporting of collected data to command-and-control infrastructure. It can also self-update, execute additional PowerShell, and retrieve and run further binaries, enabling flexible post-exploitation and malware delivery. Observed intrusion chains attributed to TA554 have relied heavily on legitimate Windows utilities and low-visibility execution methods, including scheduled-task persistence and abuse of LOLBins such as PowerShell, BITSAdmin, certutil, and native system administration tooling. In campaigns culminating in Ramnit deployment, the actor’s tooling established persistence, performed reconnaissance, exfiltrated screenshots and host data, and ultimately delivered banking Trojan functionality associated with credential theft, fraud enablement, and browser-based financial compromise. TA554 has notably targeted victims in Italy, the United Kingdom, and Canada, with a strong emphasis on financial-sector victimology and banking-themed follow-on activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
44 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses the sLoad dropper to distribute the Ramnit banking Trojan in sustained spam/phishing campaigns, including campaigns targeting financial institutions and Italian users.
Conducting geographically targeted malspam campaigns using personalized package delivery or order notification lures to deliver PowerShell downloaders including sLoad, which frequently leads to banking malware infections.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.