TA505
High ConfidenceHigh ThreatEvil Corp • GOLD TAHOE • Hive0065 • Graceful Spider
TA505 is one of the most prolific financially motivated threat actors, active since at least 2014. The group is responsible for distributing massive volumes of malicious spam carrying banking trojans like Dridex and ransomware including Locky and Clop. TA505 operates as both a direct threat and an access broker, selling network access to other criminal groups. Their operations have affected thousands of organizations worldwide, causing billions of dollars in damages through ransomware, banking fraud, and data theft.
TA505 is one of the most prolific financially motivated threat actors, active since at least 2014. The group is responsible for distributing massive volumes of malicious spam carrying banking trojans like Dridex and ransomware including Locky and Clop. TA505 operates as both a direct threat and an access broker, selling network access to other criminal groups. Their operations have affected thousands of organizations worldwide, causing billions of dollars in damages through ransomware, banking fraud, and data theft.
Target Sectors
Target Regions
Attributed to Cybercriminal (No State Sponsor) (Russia). Attribution confidence: High.
Future Outlook
TA505 is expected to continue operations targeting Financial Services sectors.
First observed activity of TA505
Continued active operations