TR is a cybercriminal malware distribution actor associated with large-scale malicious spam campaigns and email thread hijacking used to deliver initial-access malware. The actor has been linked to delivery of QakBot, IcedID, and SquirrelWaffle, and is regarded as part of the access-broker ecosystem that enables follow-on intrusions, including ransomware operations. Activity attributed to TR has included malspam campaigns, abuse of hijacked internal email reply chains, and reported brute-force activity against IMAP services. TR has also been associated with campaigns exploiting exposed Microsoft Exchange servers via ProxyLogon and ProxyShell to compromise email infrastructure and improve phishing credibility. TR’s tradecraft centers on initial compromise and malware delivery rather than public attribution to a distinct ransomware brand. Observed infection chains used malicious Office documents with VBA and Excel 4.0 macros, as well as loader execution through signed Windows utilities such as regsvr32. Campaigns attributed to TR have leveraged stolen or hijacked email conversations to impersonate trusted correspondents and increase user interaction with malicious attachments. Through its delivery of QakBot and IcedID, TR has been indirectly connected to later-stage hands-on-keyboard intrusions, credential theft, reconnaissance, persistence, lateral movement, data theft, and eventual ransomware deployment by downstream operators. No high-confidence country of origin is established from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
In November 2021, a Trend Micro report described a wave of attacks using ProxyShell and ProxyLogon vulnerabilities in exposed Microsoft Exchange servers to hijack internal email reply-chains and spread malware-laced documents.
In November 2021, a Trend Micro report described a wave of attacks using ProxyShell and ProxyLogon vulnerabilities in exposed Microsoft Exchange servers to hijack internal email reply-chains and spread malware-laced documents.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously reported as behind a November 2021 campaign exploiting exposed Microsoft Exchange servers to hijack internal email reply chains and distribute malware-laced documents.
A malware distributor associated with sending malicious spam that delivered QAKBOT and SquirrelWaffle, and reportedly conducting brute-force attacks on IMAP services.
Spam delivery operations that led to IcedID infections.
A named distribution cluster referenced as delivering QAKBOT through malspam.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.