All actors

TA505

Also reported as Spandex Tempest, Hive0065, DEV-0950, Lace Tempest, CHIMBORAZO and 21 other names. Linked to Russia by three sources.

Reports
639
Last reported
Known CVEs
490
Techniques in ATT&CK
34
Origin
Russia
ID
G0092
Merge evidence
53 alias matches

Reports per quarter

  1. 2015 Q1: 1 report
  2. 2015 Q2: no reports
  3. 2015 Q3: no reports
  4. 2015 Q4: 2 reports
  5. 2016 Q1: 1 report
  6. 2016 Q2: no reports
  7. 2016 Q3: 2 reports
  8. 2016 Q4: 5 reports
  9. 2017 Q1: 4 reports
  10. 2017 Q2: 7 reports
  11. 2017 Q3: 10 reports
  12. 2017 Q4: 4 reports
  13. 2018 Q1: 11 reports
  14. 2018 Q2: 4 reports
  15. 2018 Q3: 6 reports
  16. 2018 Q4: 7 reports
  17. 2019 Q1: 17 reports
  18. 2019 Q2: 26 reports
  19. 2019 Q3: 22 reports
  20. 2019 Q4: 26 reports
  21. 2020 Q1: 56 reports
  22. 2020 Q2: 36 reports
  23. 2020 Q3: 29 reports
  24. 2020 Q4: 53 reports
  25. 2021 Q1: 39 reports
  26. 2021 Q2: 32 reports
  27. 2021 Q3: 23 reports
  28. 2021 Q4: 33 reports
  29. 2022 Q1: 33 reports
  30. 2022 Q2: 26 reports
  31. 2022 Q3: 9 reports
  32. 2022 Q4: 16 reports
  33. 2023 Q1: 11 reports
  34. 2023 Q2: 10 reports
  35. 2023 Q3: 7 reports
  36. 2023 Q4: 3 reports
  37. 2024 Q1: 1 report
  38. 2024 Q2: 2 reports
  39. 2024 Q3: 1 report
  40. 2024 Q4: 1 report
  41. 2025 Q1: no reports
  42. 2025 Q2: 2 reports
  43. 2025 Q3: 3 reports
  44. 2025 Q4: no reports
  45. 2026 Q1: 1 report
  46. 2026 Q2: 56 reports
  47. 2026 Q3: 1 report
Dated reports, 2015 Q1 to 2026 Q3.

Techniques seen in the last two years

Show all 46 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 25 techniques Show fewer

CVEs named in reports

Show all 490 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. TA505 Continues to Infect Networks With SDBbot RAT

    date ORKL added it fromORKL

  2. Amadey (Malware Family)

    date ORKL added it fromORKL

Show all 639 reports Show fewer
  1. Gandcrab (Malware Family)

    date ORKL added it fromORKL

  2. Binary Defense

    date ORKL added it fromORKL

  3. Research, News, and Perspectives

    date ORKL added it fromORKL

  4. FlawedAmmyy (Malware Family)

    date ORKL added it fromORKL

  5. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  6. Clop (Malware Family)

    date ORKL added it fromORKL

  7. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  8. Dridex (Malware Family)

    date ORKL added it fromORKL

  9. Triton (Malware Family)

    date ORKL added it fromORKL

  10. Zeus (Malware Family)

    date ORKL added it fromORKL

  11. Locky (Malware Family)

    date ORKL added it fromORKL

  12. TA505, Graceful Spider, Gold Evergreen

    date ORKL added it fromORKL

  13. A Truly Graceful Wipe Out

    publisher's date The DFIR Report fromORKLDFIR Report

  14. Elastic Security Labs discovers the LOBSHOT malware

    date in the title fromORKL

  15. How Microsoft names threat actors

    date in the title fromORKL

  16. Investigating Intrusions From Intriguing Exploits

    date in the title fromORKL

  17. Breaking the silence - Recent Truebot activity

    date in the title fromORKL

  18. GraceWire / FlawedGrace malware adventure

    Malpedia library date fromORKL

  19. LockBit 3.0 Being Distributed via Amadey Bot

    date in the title fromORKL

  20. RedSense

    Malpedia library date fromORKL

  21. Amadey Bot Being Distributed Through SmokeLoader

    date in the title fromORKL

  22. SocGholish Campaigns and Initial Access Kit

    date in the title fromORKL

  23. 2021trends.pdf

    Malpedia library date fromORKL

  24. Ransomware Spotlight- Clop

    date in the title fromORKL

  25. RedSense

    Malpedia library date fromORKL

  26. Annual Threat trends 2021

    date in the title fromORKL

  27. Malware Headliners- Dridex

    date in the title fromORKL

  28. Tracking a P2P network related to TA505

    date in the title fromORKL

  29. FINDING BEACONS IN THE DARK 1650728751599

    Malpedia library date BlackBerry fromORKLCCS '25 data

  30. Whatta TA_ TA505 Ramps Up Activity, Delivers New FlawedGrace Variant _ Proofpoint US

    date in the CCS '25 data Proofpoint fromORKLCCS '25 data

  31. ASEC_REPORT_vol.103_ENG

    date in the CCS '25 data AhnLab fromORKLCCS '25 data

  32. Malware Masquerades as Privacy Tool

    date in the title fromORKL

  33. Intel 471

    Malpedia library date fromORKL

  34. Threat Assessment- Clop Ransomware

    date in the title fromORKL

  35. mtrends-2021

    file creation date fromORKL

  36. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  37. The_CrowdStrike_2021_Global_Threat_Report

    file creation date fromORKL

  38. De ataque con Malware a incidente de Ransomware

    date in the title fromORKL

  39. DRIDEX Stopping Serial Killer- Catching the Next Strike

    date in the title fromORKL

  40. Using Qiling Framework to Unpack TA505 packed samples

    date in the title fromORKL

  41. TA505- A Brief History Of Their Time

    date in the title fromORKL

  42. TA505_ A Brief History Of Their Time – Fox-IT International blog

    date in the CCS '25 data Fox-IT fromORKLCCS '25 data

  43. TinyPOS and ProLocker- An Odd Relationship

    date in the title fromORKL

  44. Leakware-Ransomware-Hybrid Attacks

    date in the title fromORKL

  45. Trickbot disrupted

    date in the title fromORKL

  46. TA505 targets the Americas in a new campaign

    date in the title fromORKL

  47. TA505 targets the Americas in a new campaign

    date in the title fromORKL

  48. Maksim Yakubets

    Malpedia library date fromORKL

  49. Reverse Engineering Dridex and Automating IOC Extraction

    date in the title fromORKL

  50. CERTFR-2020-CTI-009

    file creation date fromORKL

  51. Dridex – From Word to Domain Dominance

    date in the title fromORKL

  52. CERTFR-2020-CTI-008

    Malpedia library date CrowdStrike fromORKLCCS '25 data

  53. Flowspec - TA505s bulletproof hoster of choice

    date in the title fromORKL

  54. ServHelper- Hidden Miners

    date in the title fromORKL

  55. Clop, Clop! It’s a TA505 HTML malspam analysis

    date in the title fromORKL

  56. TA505 returns with a new bag of tricks

    Malpedia library date fromORKL

  57. TA505 returns with a new bag of tricks

    date in the title fromORKL

  58. Operation TA505- network infrastructure. Part 3.

    date in the title fromORKL

  59. A brief history of TA505

    date in the title fromORKL

  60. TA505 Continues to Infect Networks With SDBbot RAT

    date in the title fromORKL

  61. GuLoader delivers RATs and Spies in Disguise

    date in the title fromORKL

  62. SDBbot Unpacker

    date in the title fromORKL

  63. 200407-MWB-COVID-White-Paper_Final

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  64. Coronavirus Threat Landscape Update

    date in the title fromORKL

  65. cybersecurity-threatscape-2019-q4-eng

    file creation date fromORKL

  66. Breaking TA505’s Crypter with an SMT Solver

    date in the title fromORKL

  67. Report2020CrowdStrikeGlobalThreatReport

    Malpedia library date fromORKL

  68. Lexfo-WhitePaper-The_Lazarus_Constellation

    file creation date fromORKL

  69. 2020.02.22_APT_threat_report_2019_CN_version

    Malpedia library date fromORKL

  70. 2020_State-of-Malware-Report.pdf

    Malpedia library date fromORKL

  71. STOMP 2 DIS- Brilliance in the (Visual) Basics

    date in the title fromORKL

  72. Forensics Report True Hedge

    Malpedia library date fromORKL

  73. Inside of CL0P’s ransomware operation

    Malpedia library date fromORKL

  74. Inside of CL0P’s ransomware operation

    date in the title fromORKL

  75. TAFOF Unpacker

    date in the title fromORKL

  76. Threat Spotlight- Amadey Bot Targets Non-Russian Users

    date in the title fromORKL

  77. Clop ransomware Notes

    date in the title fromORKL

  78. Binary Defense

    Malpedia library date fromORKL

  79. An Updated ServHelper Tunnel Variant

    date in the title fromORKL

  80. cybersecurity-threatscape-2019-q3-eng

    file creation date fromORKL

  81. TA505 Get2 Analysis

    date in the title fromORKL

  82. TA-505 Cybercrime on System Integrator Companies

    date in the CCS '25 data Microsoft fromORKLCCS '25 data

  83. Shikata Ga Nai Encoder Still Going Strong

    date in the title fromORKL

  84. TA505 Timeline

    date in the title fromORKL

  85. Analysis of the new TA505 campaign

    date in the title fromORKL

  86. SectorJ04 Group’s Increased Activity in 2019

    date in the title fromORKL

  87. SectorJ04 Group’s Increased Activity in 2019

    date in the CCS '25 data ThreatRecon fromORKLCCS '25 data

  88. Silence 2.0: Going Global

    Malpedia library date fromORKL

  89. The 2019 Resurgence of Smokeloader

    date in the title fromORKL

  90. Latest Spam Campaigns from TA505 Now Using New Malware Tools Gelup and FlowerPippi

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  91. Latest Spam Campaigns from TA505 Now Using New Malware Tools Gelup and FlowerPippi

    Malpedia library date Trend Micro fromORKLCCS '25 data

  92. Latest Spam Campaigns from TA505 Now Using New Malware Tools Gelup and FlowerPippi

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  93. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  94. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  95. TA505 is Expanding its Operations

    date in the CCS '25 data Yoroi fromORKLCCS '25 data

  96. TA505 is Expanding its Operations

    date in the title fromORKL

  97. FlawedAmmyy

    date in the title fromORKL

  98. The Stealthy Email Stealer in the TA505 Arsenal

    date in the title fromORKL

  99. Analyzing Amadey

    date in the title fromORKL

  100. CyberInt_Legit Remote Access Tools Turn Into Threat Actors' Tools_Report

    date in the CCS '25 data CyberInt fromORKLCCS '25 data

  101. OSINT Reporting Regarding DPRK and TA505 Overlap

    date in the title fromORKL

  102. 2018 Master Table

    file creation date fromORKL

  103. TA505 Crime Gang Debuts Brand-New ServHelper Backdoor

    date in the title fromORKL

  104. tRat- New modular RAT appears in multiple email campaigns

    date in the title fromORKL

  105. ce44cbda9fdc061050c1d2a5dec0270874a9dc85.pdf

    Malpedia library date fromORKL

  106. BlackTDS

    date in the CCS '25 data Proofpoint fromORKLCCS '25 data

  107. Leaked Ammyy Admin Source Code Turned into Malware

    date in the title fromORKL

  108. Holiday lull- Not so much

    date in the title fromORKL

  109. Threat Actor Profile- TA505, From Dridex to GlobeImposter

    date in the title fromORKL

  110. Informe_Evoluci%C3%B3n_Trickbot.pdf

    Malpedia library date fromORKL

  111. Evolution of the GOLD EVERGREEN Threat Group

    date in the title fromORKL

  112. TrickBot Banker Insights | NETSCOUT

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.