TA551
Medium ConfidenceMedium ThreatShathak • UNC2420 • Gold Cabin
TA551, also known as Shathak, is a financially motivated threat actor that operates as an initial access broker, distributing malware through malicious email campaigns. Active since at least 2016, the group uses thread-hijacking techniques and password-protected archives to evade detection. TA551 has distributed various malware families including IcedID, Ursnif, and Valak, often selling the resulting network access to ransomware operators.
TA551, also known as Shathak, is a financially motivated threat actor that operates as an initial access broker, distributing malware through malicious email campaigns. Active since at least 2016, the group uses thread-hijacking techniques and password-protected archives to evade detection. TA551 has distributed various malware families including IcedID, Ursnif, and Valak, often selling the resulting network access to ransomware operators.
Target Sectors
Target Regions
Attributed to Cybercriminal (No State Sponsor) (Unknown). Attribution confidence: Medium.
Future Outlook
TA551 is expected to continue operations targeting All Sectors.
First observed activity of TA551
Continued active operations