Threat Actor ๐ท๐บ Russia
TA505
Also known as: SectorJ04 ยท SectorJ04 Group ยท GRACEFUL SPIDER ยท GOLD TAHOE ยท Dudear ยท G0092 ยท ATK103 ยท Hive0065 ยท CHIMBORAZO ยท Spandex Tempest
TA505, the name given by Proofpoint, has been in the cybercrime business for at least four years. This is the group behind the infamous Dridex banking trojan and Locky ransomware, delivered through malicious email campaigns via Necurs botnet. Other malware associated with TA505 include Philadelphia and GlobeImposter ransomware families.