Uptime Hamster: 10d 12h 22mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza TA516

TA516

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: SmokingDro, Remocs, lo que sugiere una actividad crónica, bien organizada
Ver en IntelTracker → APTTrail →
TA516 is a financially motivated threat actor that first emerged around 2016. This group primarily focuses on financial crime and monetary gain through the distribution of various malware. It is known for distributing SmokeLoader, an intermediate downloader, which subsequently delivers banking Trojans and cryptocurrency miners. TA516 distinguishes itself by its consistent use of social engineering via macro-enabled documents and malicious JavaScript hosted on Google Drive for initial system compromise. The group is also identified by the alias SmokingDro.

Aliases del actor

SmokingDroRemocslo que sugiere una actividad crónicabien organizada

Actores similares

lunalockransomware · 2Purchase Technical Dataactor · 1Masquerade File Typeactor · 1eloquent-pandaactor · 1lunar-spideractor · 1anunakactor · 1Caramel Tsunamiapt · 0Carmine Tsunamiapt · 0LUNAR SPIDERapt · 0Water Bakunawaapt · 0
Tecnicas MITRE
T1059, T1566.001, T1071.001
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
2
Actualizado
Wed, 01 Ju