Development of the activity of the TA505 cybercriminal group
ID: 82f99c03-1867-41b6-9c74-0ff2f0987d32
STIX ID: report--82f99c03-1867-41b6-9c74-0ff2f0987d32
Threat Score
80/100
Uploaded: 2026-07-30
Published Date: 2026-07-30
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
This ANSSI report analyzes TA505, a prolific cybercriminal intrusion set active from 2014 through 2020, documenting its evolution from distributing banking trojans and Locky/other ransomware via the Necurs botnet to using staged loaders and backdoors (Get2, FlawedAmmyy, SDBbot, ServHelper, FlawedGrace) to achieve broad network compromise and deploy Clop ransomware; the report covers infection vectors (phishing with HTML/JS redirects), reconnaissance and lateralization (Mimikatz, Cobalt Strike, AD enumeration), infrastructure practices (short-lived domains, signed binaries, Minedoor packer), observed targets and campaigns, and likely links to other criminal groups (FIN7, Silence) and potential clients like Lazarus.
