Threat Intelligence Tarot
cups · 5
Criminal (Russian-speaking, suspected)
G0092★★★★★
risk 4/5
✦ The Broker ✦
TA505
Hive0065 · GRACEFUL SPIDER
Financial institutionsHealthcareRetailGlobal250+ countries targeted
Active since ~2014 · Malware distribution as a service, Ransomware delivery, Banking trojan deployment
TA505 is infrastructure. It does not specialize in one crime - it specializes in delivery. The Broker runs the largest spam and malware distribution operation ever documented, renting its capacity to ransomware groups, banking trojan operators, and whoever pays. It is a criminal logistics company.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆Dridex banking trojan distribution - billions in banking fraud
- ◆Locky ransomware global campaigns
- ◆FlawedAmmyy RAT and ServHelper malware distribution
- ◆Clop ransomware affiliate operations
Defenses
- ▸Email filtering with attachment sandboxing and URL scanningCIS Control 9 ↗
- ▸User training on malicious macro-enabled documentsNIST SP 800-50 ↗
- ▸Macro execution disabled by policy in Microsoft OfficeCIS Control 2 ↗
- ▸Network monitoring for Dridex and Clop C2 infrastructureNIST CSF: DE.CM ↗
Reversed: Their Weakness
TA505's scale - the sheer volume of malicious email - ultimately generates extensive telemetry that feeds detection systems globally. The same volume that makes it dangerous makes it one of the best-documented threat actors, with indicator sharing across the security industry.
Share this adversary profile
swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.