logo

TA505: A Brief History Of Their Time

ID: 5770d3aa-770c-5b02-b73c-0e4002e568b9

STIX ID: report--5770d3aa-770c-5b02-b73c-0e4002e568b9

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2020-11-16

Date Updated: 2026-04-27

Author: Antonis Terefos

...
...

Fox-IT analyses TA505 operations (2019–2020), describing how targeted HTML/XLS malspam deploys the Get2/GetandGo loader which fetches the SDBbot RAT, enabling lateral movement and eventual deployment of Clop ransomware; the report covers custom packing/obfuscation techniques, campaign timelines, working hours, 'dransom' durations, and the group's public data-leak site used for extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.