The TA551 (also tracked as Shathak) threat group used large-scale malspam campaigns to distribute malware including Ursnif, Valak, IcedID, and Qakbot through hijacked email threads and password-protected ZIP attachments. The lures typically contained malicious Microsoft Word documents that urged users to enable macros, after which the infection chain launched follow-on components such as HTA files, obfuscated JavaScript, XSL files, and DLL payloads executed with Windows utilities including regsvr32.exe and rundll32.exe. Researchers also observed language-specific campaigns, including German-language spam, and noted that Valak frequently acted as both an information stealer and loader for additional malware such as NetSupport Manager RAT and IcedID.
Analysis of TA551 infrastructure found repeatable patterns across hundreds of domains, including registrar and DNS-provider preferences, TLS certificate behavior, and numeric naming conventions that helped identify likely new campaign domains before they were widely used. Defenders were advised to watch for suspicious process chains such as Word spawning mshta.exe, followed by regsvr32.exe, as well as file-type masquerading, scheduled-task persistence, registry modifications, Alternate Data Streams, and Temp-directory artifacts associated with Ursnif and Valak infections.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
HP Wolf Security found that TA551's preferred DNS provider shifted over time, with DNSPod disappearing after mid-November and GeoScaling and Cloudflare appearing instead.
HP Wolf Security analyzed about 500 known TA551 domains spanning July 2020 to December 2020 to identify recurring registration, DNS, and TLS patterns tied to the group's payload-hosting infrastructure.
Unit 42 said Valak became increasingly prevalent from April through June 2020, largely through distribution by the Shathak/TA551 malspam network.
Unit 42 reported that passwords for ZIP attachments in Shathak/TA551 campaigns had been unique per recipient since May 2020, indicating a change in delivery tradecraft.
Unit 42 reported that since April 2020, Valak became the most common malware distributed by Shathak/TA551, replacing Ursnif as the group's primary payload.
On 2020-01-21, a German-language malspam wave used hijacked email chains and password-protected ZIP attachments to distribute Ursnif. Victims were prompted to enable macros in a Word document, which dropped an XSL file, retrieved an Ursnif DLL, and executed it via rundll32.exe.
Unit 42 reported that Valak was documented as follow-up malware during Ursnif infections in December 2019, showing its early role alongside TA551-delivered malware chains.
Unit 42 said Valak was first observed in late 2019 as an information stealer and malware loader. It was also first detected by Proofpoint's ET Pro ruleset in October 2019.
HP Wolf Security reported that TA551 had been observed distributing malware including Ursnif since the beginning of 2019. Unit 42 also noted that before April 2020, Shathak/TA551 primarily distributed Ursnif.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
threatresearch.ext.hp.com
Open sourceunit42.paloaltonetworks.com
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.