Threat researchers and incident responders linked TA505 to a years-long progression from massive malspam operations delivering Dridex, Locky, Jaff, GlobeImposter, and other payloads to more targeted intrusions aimed at full-network compromise and ransomware deployment. Early campaigns relied heavily on the Necurs botnet and phishing lures with malicious PDFs, macro-enabled Word documents, ZIP archives, .url shortcuts, and .iqy files, while later operations introduced loaders and remote-access malware including FlawedAmmyy, Marap, FlowerPippi, and Gelup. Researchers reported that these tools supported host fingerprinting, encrypted command-and-control, persistence, privilege escalation, and delivery of follow-on payloads, showing a shift from simple malware distribution to modular access operations.
The group’s later activity culminated in enterprise-wide attacks associated with Clop ransomware, including the compromise of Maastricht University, where attackers reportedly entered through phishing, escalated privileges on an unpatched system, mapped the network, harvested credentials, and encrypted 267 Windows servers, leading the university to pay a 30 bitcoin ransom. Separate reporting on 2020 Dridex campaigns showed continued use of macro-enabled documents, PowerShell downloaders, rundll32.exe, HTTPS command-and-control, and multiple persistence mechanisms, underscoring that TA505 maintained high-volume delivery tactics even as it adopted tools such as Mimikatz, Cobalt Strike, WMIC, RDP, PowerSploit, PingCastle, and AdFind to move laterally, disable defenses, and prepare domain-wide ransomware deployment and, in some cases, extortion through stolen data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
29 events from the most recent confirmed update back to the earliest known activity.
SANS analyzed a September 2020 malspam campaign delivering Dridex through malicious Word documents with macros. Enabling macros triggered PowerShell to download a DLL installer over HTTPS, which was executed with rundll32.exe and established persistence through a Run key, scheduled task, and startup shortcut.
In March 2020, a leak site was created to publish exfiltrated data from Clop victims who refused to pay. CERT-FR assessed this as evidence that TA505 had adopted double-extortion tactics.
Maastricht University paid the attackers a 30 bitcoin ransom on December 30, 2019 to obtain file decryption and avoid rebuilding compromised systems from scratch. The university said the decision helped preserve continuity for teaching, exams, research, and salary payments.
On December 23, 2019, attackers deployed Clop ransomware across Maastricht University's Windows domain, encrypting data on 267 Windows servers and affecting part of the university's technical infrastructure. Fox-IT linked the modus operandi to TA505.
CERT-FR reported that in late 2019 and early 2020, TA505 stabilized a social-engineering chain using HTML attachments with malicious JavaScript that redirected victims through compromised websites to phishing pages impersonating services such as OneDrive, Dropbox, or Naver. Some redirection pages also used iplogger.org links to inspect visitor IP addresses.
In December 2019, CERT-XLM responded to a ransomware-related intrusion at a Belgian healthcare-sector organization allegedly conducted by TA505. The attack used large phishing waves impersonating a Onehub trial to deliver GET2 and then SDBbot, after which the attackers gained domain-wide access and spread to more than 50 systems before responders contained the operation and likely prevented ransomware deployment.
CERT-FR noted an observed TA505 use of Rapid ransomware in South Korea in December 2019. This showed the group continuing to vary ransomware payloads alongside Clop.
Fox-IT reported that the attackers moved through Maastricht University's network until November 21, 2019, when they gained administrative rights on an unpatched machine. After that, they compromised multiple servers across the university network.
According to Fox-IT, the attackers behind the later Maastricht University ransomware incident initially infiltrated the university through two phishing emails opened on October 15 and 16, 2019. This established the foothold that preceded the Clop deployment.
ANSSI reported that SDBbot, a malware family it assessed as specific to TA505, had been used by the group since September 2019. The malware appeared in TA505's post-phishing intrusion chains as part of its shift toward broader enterprise compromise.
Trend Micro observed a TA505 spam campaign on June 20 targeting Japan, the Philippines, and Argentina that used two apparently new malware families, FlowerPippi and Gelup. FlowerPippi acted as a backdoor/downloader, while Gelup used anti-analysis features, a UAC bypass, and scheduled-task persistence.
CERT-FR reported that TA505 had deployed Clop ransomware in attacks from at least February 2019. The group used tooling such as sage.exe and DeactivateDefender to prepare enterprise-wide encryption.
Proofpoint observed large Marap malware campaigns on August 10, 2018, involving millions of messages primarily targeting financial institutions. The campaigns used .iqy files, password-protected ZIPs, PDFs with embedded .iqy files, and macro-enabled Word documents, and shared many features with TA505 activity.
On March 5 and 6, 2018, Proofpoint linked massive email campaigns delivering FlawedAmmyy to TA505. The campaigns used ZIP archives containing .url shortcut files that pulled JavaScript over SMB, which then downloaded Quant Loader and FlawedAmmyy.
On March 1, 2018, Proofpoint observed another narrowly targeted FlawedAmmyy attack using a macro-enabled document named 0103_022.doc. The sample used the same command-and-control address later seen in the March 5 mass campaign.
On January 16, 2018, Proofpoint observed a narrowly targeted attack, including against the automotive industry, using a macro-enabled document to download FlawedAmmyy directly. This showed TA505 using the RAT in focused intrusion activity as well as mass spam.
Beginning in 2018, CERT-FR assessed that TA505 moved away from primarily distributing banking trojans and ransomware and toward deploying backdoors and pursuing broader information-system compromise. Since 2018, the group also increasingly pursued enterprise-wide ransomware attacks rather than single-host infections.
CERT-FR reported that Necurs became unavailable in January and February 2018, after which TA505 appeared to reduce its reliance on the botnet. Proofpoint had also noted that Necurs disruptions coincided with quiet periods in TA505 activity.
CERT-FR assesses that TA505 briefly used TrickBot in 2017, including a campaign in June 2017 targeting France and the United Kingdom. This represented another temporary shift in banking trojan payloads.
On May 11, 2017, Proofpoint detected a large campaign sending tens of millions of emails with PDF attachments containing embedded macro-enabled Word documents that downloaded Jaff ransomware. The campaign was attributed to the same actors behind Locky Affid=3 and Dridex 220/7200/7500.
Proofpoint reported that TA505 stopped distributing Dridex in July 2016 and then relied almost exclusively on Locky through December 2016. This marked a major payload transition in the group's spam operations.
Proofpoint observed Bart ransomware in TA505 activity on June 24, 2016, delivered by Rockloader as a secondary payload. Bart could encrypt files without contacting a command-and-control server.
In April 2016, Proofpoint observed TA505 introducing Rockloader as an intermediate loader for Locky, initially delivered through attached JavaScript files. This reflected the group's experimentation with modular delivery chains.
Proofpoint reported that TA505 introduced Locky ransomware in February 2016, after which it became the group's dominant payload. CERT-FR later assessed TA505 as the likely Locky affiliate number 3.
Proofpoint reported that the FlawedAmmyy remote access trojan had been used since the beginning of 2016 in both targeted phishing attacks and large-scale spam campaigns. The malware was derived from leaked Ammyy Admin source code.
Proofpoint observed TA505 using Dridex botnet ID 223 in December 2015. The botnet was associated with targeting Germany.
In October 2015, Proofpoint observed TA505 delivering the Shifu banking trojan to Japanese and UK organizations via macro-laden Office documents. This showed the group expanding beyond Dridex into other banking malware families.
Proofpoint observed TA505 using Dridex botnet ID 220 in March 2015 as part of its affiliate-style Dridex operations. CERT-FR notes this botnet was thought to contain 9,650 bots in April 2015 and mainly targeted banks, particularly in France.
Proofpoint observed TA505 distributing the Dridex banking trojan beginning on July 28, 2014, marking the group's early large-scale malware delivery activity. CERT-FR also assesses TA505 activity dates back to at least 2014 and that it began distributing Dridex in July 2014.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
intel471.com
Open sourceisc.sans.edu
Open sourcebleepingcomputer.com
Open sourceproofpoint.com
Open sourcecert.ssi.gouv.fr
Open sourcedocuments.trendmicro.com
Open sourcevblocalhost.com
Open sourcecert.ssi.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.