Highlighting TA866/Asylum Ambuscade Activity Since 2021
ID: aa17afe5-2412-5fd1-a6eb-3a3e9c6bd3b9
STIX ID: report--aa17afe5-2412-5fd1-a6eb-3a3e9c6bd3b9
Feed Name: Cisco Talos
Threat Score
This Cisco Talos report profiles TA866 (Asylum Ambuscade), a threat actor active since at least 2020 that uses malspam and malvertising to deliver multi-stage malware (WasabiSeed, Screenshotter, AHK Bot) and frequently deploys follow-on backdoors and tools (Resident, CSharp-Streamer-RAT, Cobalt Strike, Rhadamanthys) for reconnaissance and data theft; it documents TTPs, targeting (notably manufacturing, government, financial sectors), IoCs, and detection/remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
