TA516 is a financially motivated threat actor that first emerged around 2016. This group primarily focuses on financial crime and monetary gain through the distribution of various malware. It is known for distributing SmokeLoader, an intermediate downloader, which subsequently delivers banking Trojans and cryptocurrency miners. TA516 distinguishes itself by its consistent use of social engineering via macro-enabled documents and malicious JavaScript hosted on Google Drive for initial system compromise. The group is also identified by the alias SmokingDro.