logo

Highlighting TA866/Asylum Ambuscade Activity Since 2021

ID: aa17afe5-2412-5fd1-a6eb-3a3e9c6bd3b9

STIX ID: report--aa17afe5-2412-5fd1-a6eb-3a3e9c6bd3b9

Feed Name: Cisco Talos

Threat Score
78/100

Date Published: 2024-10-23

Date Updated: 2026-04-27

Author: Edmund Brumaghin

...
...

This Cisco Talos report profiles TA866 (Asylum Ambuscade), a threat actor active since at least 2020 that uses malspam and malvertising to deliver multi-stage malware (WasabiSeed, Screenshotter, AHK Bot) and frequently deploys follow-on backdoors and tools (Resident, CSharp-Streamer-RAT, Cobalt Strike, Rhadamanthys) for reconnaissance and data theft; it documents TTPs, targeting (notably manufacturing, government, financial sectors), IoCs, and detection/remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.