Uptime Hamster: 10d 7h 14mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza TA505

TA505

1 incidentes 1 paises 1 sectores apt RU Ultimo: 2026-05-25
Aliases: ATK103, CHIMBORAZO, DEV-0950, Dudear, FIN11, G0092, GOLD TAHOE, GRACEFUL SPIDER, Hive0065, Lace Tempest, SectorJ04, SectorJ04 Group, Spandex Tempest, Evil Corp, WastedLocker, Ta505, Dridex, otros
Ver en IntelTracker → APTTrail →
TA505 is a prolific, financially motivated cybercriminal group, first documented in 2014, known for its industrial-scale operations in phishing, malware distribution, and ransomware campaigns. The group has shown significant evolution, shifting from the widespread distribution of banking Trojans like Dridex to operating sophisticated ransomware-as-a-service (RaaS) models, prominently featuring the Clop ransomware strain. A defining characteristic of TA505 is its constant adaptation, regularly changing its malware, techniques, and procedures to avoid detection and maximize impact. The group distinguishes itself through the sheer volume of its malicious email campaigns and its role as an initial access broker, often selling access to compromised corporate networks to other threat actors. TA505 is also recognized by numerous aliases, including GRACEFUL SPIDER, Lace Tempest, Spandex Tempest, DEV-0950, FIN11, Evil Corp, GOLD TAHOE, GOLD EVERGREEN, Chimborazo, Hive0065, ATK103, and G0092.

Aliases del actor

ATK103CHIMBORAZODEV-0950DudearFIN11G0092GOLD TAHOEGRACEFUL SPIDERHive0065Lace TempestSectorJ04SectorJ04 GroupSpandex TempestEvil CorpWastedLockerTa505Dridexotros

Actores similares

Scattered Spideractor · 2Indrik Spideractor · 1doppel-spideractor · 1salty-spideractor · 1brain-spideractor · 1skeleton-spideractor · 1bamboo-spideractor · 1andromeda-spideractor · 1cobalt-spideractor · 1boson-spideractor · 1
Motivacion