logo

TA577 (Hive0118): The Evolving Phishing Specialist Behind Modern Malware Campaigns

ID: ac4d8018-0bd3-52e9-810b-2280c4087861

STIX ID: report--ac4d8018-0bd3-52e9-810b-2280c4087861

Feed Name: Brandefense Blog

Threat Score
75/100

Date Published: 2026-01-20

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

TA577 (aka Hive0118) is a Russian-speaking cybercrime access broker active since mid‑2020 that runs large-scale phishing campaigns (reply-chain injection, HTML smuggling, containerized payloads) to deliver loaders (previously QakBot/IcedID, now Pikabot and Latrodectus), harvest NTLM hashes and credentials, and monetize access via partnerships with ransomware affiliates (notably observed overlap with Black Basta); the report outlines their evolution, TTPs, notable operations (2023–2025), IoC patterns, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.