TA505: A Brief History Of Their Time
ID: 5770d3aa-770c-5b02-b73c-0e4002e568b9
STIX ID: report--5770d3aa-770c-5b02-b73c-0e4002e568b9
Feed Name: Fox-IT blog
Threat Score
Fox-IT analyses TA505 operations (2019–2020), describing how targeted HTML/XLS malspam deploys the Get2/GetandGo loader which fetches the SDBbot RAT, enabling lateral movement and eventual deployment of Clop ransomware; the report covers custom packing/obfuscation techniques, campaign timelines, working hours, 'dransom' durations, and the group's public data-leak site used for extortion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
