TA551, Shathak

Description

(Palo Alto) TA551 (also known as Shathak) is an email-based malware distribution campaign that often targets English-speaking victims. The campaign discussed in this blog has targeted German, Italian and Japanese speakers. TA551 has historically pushed different families of information-stealing malware like Ursnif and Valak. After mid-July 2020, this campaign has exclusively pushed IcedID malware, another information stealer.

Names

NameName-Giver
TA551Proofpoint
Gold CabinSecureWorks
Shathak?
Monster LibraPalo Alto

Country

Motivation

  • Financial gain

First Seen

2016

Tools

Operations

Information

Mitre Attack

Playbook

Other Information

Uuid

269da320-1b20-4721-9bd6-17e0a355fe7d

Last Card Change

2024-03-10