logo

Tracking a P2P network related to TA505

ID: 523645db-385d-5319-83e9-3a3104093ac9

STIX ID: report--523645db-385d-5319-83e9-3a3104093ac9

Feed Name: Fox-IT blog

Threat Score
78/100

Date Published: 2021-12-02

Date Updated: 2026-04-27

Author: Joost Jansen

...
...

NCC Group details technical analysis linking P2P RAT binaries, a Necurs-style downloader and signed drivers to TA505 and the Grace (FlawedGrace) developer(s). The report describes installation and persistence behaviors, RC4/RC4-like decryption and XOR routines, driver-based process/service filtering and injection, the UDP peer-to-peer protocol and record file format used to exchange stolen data and updates, and provides IoCs (node IPs and SHA-1 hashes) with medium–high confidence attribution to TA505’s broader infostealer and ransomware operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.