logo

Development of the activity of the TA505 cybercriminal group

ID: 82f99c03-1867-41b6-9c74-0ff2f0987d32

STIX ID: report--82f99c03-1867-41b6-9c74-0ff2f0987d32

Threat Score

80/100

Uploaded: 2026-07-30

Published Date: 2026-07-30

Last Modified Date: 2026-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
This ANSSI report analyzes TA505, a prolific cybercriminal intrusion set active from 2014 through 2020, documenting its evolution from distributing banking trojans and Locky/other ransomware via the Necurs botnet to using staged loaders and backdoors (Get2, FlawedAmmyy, SDBbot, ServHelper, FlawedGrace) to achieve broad network compromise and deploy Clop ransomware; the report covers infection vectors (phishing with HTML/JS redirects), reconnaissance and lateralization (Mimikatz, Cobalt Strike, AD enumeration), infrastructure practices (short-lived domains, signed binaries, Minedoor packer), observed targets and campaigns, and likely links to other criminal groups (FIN7, Silence) and potential clients like Lazarus.