TA551
[TA551](https://attack.mitre.org/groups/G0127) is a financially-motivated threat group that has been active since at least 2018. (Citation: Secureworks GOLD CABIN) The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns. (Citation: Unit 42 TA551 Jan 2021)
Properties
- stix_id
- intrusion-set--94873029-f950-4268-9cfd-5032e15cb182
- signal_observed_at
- 2026-09-11T17:55:00+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (14)
Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns wi
Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather th
Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external ad
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to ope
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masqueradin
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are sev
Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. [Shared Modules](https://at
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a sp
Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect. Command
Adversaries may use steganography techniques in order to prevent the detection of hidden information. Steganographic techniques can be used to hide da
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with exi
Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the prima
Software & Tools (5)
[IcedID](https://attack.mitre.org/software/S0483) is a modular banking malware designed to steal financial information that has been observed in the w
[QakBot](https://attack.mitre.org/software/S0650) is a modular banking trojan that has been used primarily by financially-motivated actors since at le
[Sliver](https://attack.mitre.org/software/S0633) is an open source, cross-platform, red team command and control (C2) framework written in Golang. [S
[Ursnif](https://attack.mitre.org/software/S0386) is a banking trojan and variant of the Gozi malware observed being spread through various automated
[Valak](https://attack.mitre.org/software/S0476) is a multi-stage modular malware that can function as a standalone information stealer or downloader,
Explore this actor's full graph with Ninja Signal