All actors

TA551

Also reported as GOLD CABIN, Monster Libra, Shathak, Shakthak, ATK236 and 1 other name. Linked to Russia by one source.

Reports
689
Last reported
Known CVEs
225
Techniques in ATT&CK
14
Origin
Russia
ID
G0127
Merge evidence
13 alias matches

Reports per quarter

  1. 2009 Q2: 1 report
  2. 2009 Q3: no reports
  3. 2009 Q4: 1 report
  4. 2010 Q1: no reports
  5. 2010 Q2: 2 reports
  6. 2010 Q3: no reports
  7. 2010 Q4: 1 report
  8. 2011 Q1: no reports
  9. 2011 Q2: 1 report
  10. 2011 Q3: no reports
  11. 2011 Q4: no reports
  12. 2012 Q1: no reports
  13. 2012 Q2: no reports
  14. 2012 Q3: no reports
  15. 2012 Q4: no reports
  16. 2013 Q1: no reports
  17. 2013 Q2: no reports
  18. 2013 Q3: no reports
  19. 2013 Q4: no reports
  20. 2014 Q1: no reports
  21. 2014 Q2: no reports
  22. 2014 Q3: no reports
  23. 2014 Q4: no reports
  24. 2015 Q1: no reports
  25. 2015 Q2: 1 report
  26. 2015 Q3: no reports
  27. 2015 Q4: no reports
  28. 2016 Q1: 2 reports
  29. 2016 Q2: 1 report
  30. 2016 Q3: 1 report
  31. 2016 Q4: 1 report
  32. 2017 Q1: no reports
  33. 2017 Q2: 6 reports
  34. 2017 Q3: 1 report
  35. 2017 Q4: 6 reports
  36. 2018 Q1: 4 reports
  37. 2018 Q2: 1 report
  38. 2018 Q3: 6 reports
  39. 2018 Q4: 4 reports
  40. 2019 Q1: 12 reports
  41. 2019 Q2: 15 reports
  42. 2019 Q3: 7 reports
  43. 2019 Q4: 9 reports
  44. 2020 Q1: 25 reports
  45. 2020 Q2: 16 reports
  46. 2020 Q3: 29 reports
  47. 2020 Q4: 35 reports
  48. 2021 Q1: 45 reports
  49. 2021 Q2: 40 reports
  50. 2021 Q3: 19 reports
  51. 2021 Q4: 55 reports
  52. 2022 Q1: 59 reports
  53. 2022 Q2: 73 reports
  54. 2022 Q3: 35 reports
  55. 2022 Q4: 27 reports
  56. 2023 Q1: 35 reports
  57. 2023 Q2: 23 reports
  58. 2023 Q3: 23 reports
  59. 2023 Q4: 8 reports
  60. 2024 Q1: 16 reports
  61. 2024 Q2: 12 reports
  62. 2024 Q3: 3 reports
  63. 2024 Q4: 4 reports
  64. 2025 Q1: 1 report
  65. 2025 Q2: 2 reports
  66. 2025 Q3: 1 report
  67. 2025 Q4: 2 reports
  68. 2026 Q1: no reports
  69. 2026 Q2: 18 reports
Dated reports, 2009 Q2 to 2026 Q2.

Techniques seen in the last two years

Show all 14 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 225 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Emutet

    date ORKL added it fromORKL

  2. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  3. BazarBackdoor (Malware Family)

    date ORKL added it fromORKL

Show all 689 reports Show fewer
  1. IcedID (Malware Family)

    date ORKL added it fromORKL

  2. BumbleBee (Malware Family)

    date ORKL added it fromORKL

  3. Fork in the Ice- The New Era of IcedID

    date in the title fromORKL

  4. Unwrapping Ursnifs Gifts

    publisher's date The DFIR Report fromORKLDFIR Report

  5. VMware Brochure Template US Letter

    Malpedia library date fromORKL

  6. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  7. RedSense

    Malpedia library date fromORKL

  8. IcedID (Bokbot) with Dark VNC and Cobalt Strike

    date in the title fromORKL

  9. Qakbot report

    Malpedia library date fromORKL

  10. SVCReady- A New Loader Gets Ready

    date in the title fromORKL

  11. Malware Analysis- Trickbot

    date in the title fromORKL

  12. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  13. CERT-UA

    Malpedia library date fromORKL

  14. New Conversation Hijacking Campaign Delivering IcedID

    date in the title fromORKL

  15. Intelligence Insights- January 2022

    date in the title fromORKL

  16. How the

    Malpedia library date fromORKL

  17. TA551 (Shathak) pushes IcedID (Bokbot)

    date in the title fromORKL

  18. CONTInuing the Bazar Ransomware Story

    date in the title fromORKL

  19. RedSense

    Malpedia library date fromORKL

  20. Intelligence Insights- November 2021

    date in the title fromORKL

  21. CERTFR-2021-CTI-009

    Malpedia library date fromORKL

  22. Digital banking fraud- how the Gozi malware works

    date in the title fromORKL

  23. TA551 Uses ‘SLIVER’ Red Team Tool in New Activity

    date in the title fromORKL

  24. Case Study- From BazarLoader to Network Reconnaissance

    date in the title fromORKL

  25. Intelligence Insights- September 2021

    date in the title fromORKL

  26. Detecting TA551 domains

    date in the title fromORKL

  27. REvil-ution – A Persistent Ransomware Operation

    date in the title fromORKL

  28. From Word to Lateral Movement in 1 Hour

    date in the title fromORKL

  29. The First Step- Initial Access Leads to Ransomware

    date in the title fromORKL

  30. An Encounter With TA551-Shathak

    date in the title fromORKL

  31. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  32. Botnet-update-Q1-2021.pdf

    Malpedia library date fromORKL

  33. The rise of QakBot

    date in the title fromORKL

  34. A Spike in BazarCall and IcedID Activity Detected in March

    date in the title fromORKL

  35. 2021-Threat-Detection-Report

    file creation date fromORKL

  36. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  37. TA551

    date in the title fromORKL

  38. Binary Defense

    Malpedia library date fromORKL

  39. So Unchill Melting UNC2198 ICEDID to Ransomware Operations

    date in the title fromORKL

  40. TA551- Email Attack Campaign Switches from Valak to IcedID

    date in the title fromORKL

  41. Expanding Range and Improving Speed- A RansomExx Approach

    date in the title fromORKL

  42. The Many Faces of Emotet

    Malpedia library date fromORKL

  43. 2020-q2-spamhaus-botnet-threat-report.pdf

    Malpedia library date fromORKL

  44. CERTFR-2020-CTI-008

    Malpedia library date CrowdStrike fromORKLCCS '25 data

  45. vmwcb-report-modern-bank-heists-2020.pdf

    Malpedia library date fromORKL

  46. Dissecting Emotet - Part 2

    Malpedia library date fromORKL

  47. 2020_State-of-Malware-Report.pdf

    Malpedia library date fromORKL

  48. Dissecting Emotet – Part 1

    Malpedia library date fromORKL

  49. Forensics Report True Hedge

    Malpedia library date fromORKL

  50. News Archiv

    Malpedia library date fromORKL

  51. Emotet Adds New Evasion Technique

    Malpedia library date fromORKL

  52. SAS2019 Presentation

    file creation date fromORKL

  53. Qakbot, Data Thief Unmasked: Part I

    Malpedia library date fromORKL

  54. Qakbot Steals 2GB of Confidential Data per Week

    Malpedia library date fromORKL

  55. Qakbot, Data Thief Unmasked: Part II

    Malpedia library date fromORKL

  56. W32.Qakbot | Symantec

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.