Cybersecurity researchers have identified a new threat actor, TA585, which has been actively delivering the MonsterV2 malware through a series of sophisticated phishing campaigns. TA585 distinguishes itself by managing its entire attack chain, from infrastructure setup and email delivery to malware installation, without relying on third-party distribution services or initial access brokers. The group has been observed using U.S. Internal Revenue Service (IRS) themed phishing lures to entice victims into clicking malicious links. These links often direct users to PDFs that further redirect to web pages employing the ClickFix social engineering tactic, which prompts users to execute malicious commands via the Windows Run dialog or PowerShell terminal. The initial PowerShell command triggers a secondary script that ultimately deploys MonsterV2 on the victim's system. In later campaigns, TA585 shifted tactics to use malicious JavaScript injections on legitimate websites, presenting fake CAPTCHA overlays to initiate the infection process. This approach also leverages ClickFix to deliver the malware payload. MonsterV2, also known as Aurotun Stealer, is a remote access trojan (RAT), stealer, and loader, first advertised on criminal forums in February 2025. The malware is notable for its high price and limited user base, with TA585 being one of the few actors deploying it. MonsterV2 is designed to avoid infecting systems located in Commonwealth of Independent States (CIS) countries, demonstrating a level of geographic targeting. Prior to adopting MonsterV2, TA585 campaigns distributed other malware such as Lumma Stealer, indicating a shift in their preferred payloads. The group’s use of web injection and filtering checks adds complexity to their attack chains, making detection and mitigation more challenging. Researchers have highlighted TA585’s innovation in the constantly evolving cybercrime landscape, noting their deviation from the typical "gig economy" model of cybercrime by maintaining end-to-end control over their operations. The campaigns have evolved over time, with new delivery techniques and social engineering tactics being introduced to increase infection rates. The technical sophistication of TA585’s infrastructure and delivery methods underscores the growing threat posed by self-sufficient cybercriminal groups. Security teams are advised to monitor for indicators of compromise related to MonsterV2 and to educate users about phishing tactics involving IRS-themed lures and fake CAPTCHA overlays. The emergence of TA585 and its operational model signals a trend toward more autonomous and innovative threat actors in the cybercrime ecosystem. Ongoing research and intelligence sharing are critical to tracking the evolution of TA585 and mitigating the risks associated with MonsterV2 and similar malware families.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
On October 3, 2025, Proofpoint published research on newly named threat actor TA585, describing it as an unusually self-sufficient cybercriminal operation that controls most of its attack chain end-to-end and frequently deploys MonsterV2.
TA585 began using GitHub issue-tagging abuse to send victims legitimate GitHub notification emails containing links to actor-controlled sites. The lures were crafted to resemble security alerts and were used to deliver malware including Rhadamanthys through ClickFix-style mechanisms.
Proofpoint reported that TA585 initially delivered Lumma Stealer but changed to using MonsterV2 in May 2025 as a primary payload in its ClickFix campaigns.
In April 2025, TA585 used malicious JavaScript injected into legitimate websites to display fake CAPTCHA overlays that tricked visitors into running PowerShell commands, enabling malware delivery after filtering and verification checks.
During February and March 2025, researchers observed U.S. government-themed phishing campaigns using IRS and SBA lures that led victims to ClickFix-style pages and delivered MonsterV2. These campaigns were observed but not attributed to a tracked actor.
MonsterV2, a malware-as-a-service offering also known as Aurotun Stealer, was being sold on criminal forums as a RAT, stealer, and loader by at least February 2025.
PRODAFT reported that the CoreSecThree framework, later linked by Proofpoint to TA585 web-inject and fake GitHub alert activity, has been active since February 2022 and used to distribute stealer malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourcescworld.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.