TA551
Also reported as GOLD CABIN, Monster Libra, Shathak, Shakthak, ATK236 and 1 other name. Linked to Russia by one source.
Reports per quarter
Techniques seen in the last two years
- T1003.006 1 report reports only
- T1010 1 report reports only
- T1027 1 report reports only
- T1027.005 1 report reports only
- T1033 1 report reports only
- T1055 1 report reports only
- T1071.001 1 report in ATT&CK
- T1082 1 report reports only
- T1083 1 report reports only
- T1112 1 report reports only
Show all 14 techniques Show fewer
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2003-1138
- CVE-2005-1380
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
- CVE-2010-0817
- CVE-2010-3333 KEV
- CVE-2010-3936
- CVE-2010-4398 KEV
- CVE-2011-0609 KEV
Show all 225 CVEs Show fewer
- CVE-2011-0611 KEV
- CVE-2011-1264
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-3544 KEV
- CVE-2011-4369
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0507 KEV ransomware
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-5469
- CVE-2012-5687
- CVE-2013-0074 KEV ransomware
- CVE-2013-0422 KEV ransomware
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2551 KEV ransomware
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3897 KEV
- CVE-2013-3906 KEV
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-5947
- CVE-2013-7331 KEV
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-0346
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-2962
- CVE-2014-3567
- CVE-2014-4019
- CVE-2014-4076
- CVE-2014-4114 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-8361 KEV
- CVE-2014-8439 KEV
- CVE-2014-9583
- CVE-2015-0096
- CVE-2015-0313 KEV
- CVE-2015-0554
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2051 KEV
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3105
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2017-0068
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-14100
- CVE-2017-15399
- CVE-2017-5638 KEV ransomware
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10561 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-13374 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-6882 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0752 KEV ransomware
- CVE-2019-1108
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-1181
- CVE-2019-1224
- CVE-2019-1225
- CVE-2019-1579 KEV ransomware
- CVE-2019-1653 KEV
- CVE-2019-17026 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2725 KEV ransomware
- CVE-2019-6703
- CVE-2019-7609 KEV
- CVE-2019-9489
- CVE-2019-9670 KEV
- CVE-2020-0609
- CVE-2020-0610
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-10826
- CVE-2020-10827
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-12061
- CVE-2020-12695
- CVE-2020-13756
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-1664
- CVE-2020-16896
- CVE-2020-17144 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-4006 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-22986 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26427
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-36942 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-41379 KEV ransomware
- CVE-2021-42278 KEV ransomware
- CVE-2021-42287 KEV ransomware
- CVE-2021-42321 KEV ransomware
- CVE-2021-43936
- CVE-2021-44077 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2022-24086 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2022-41049 KEV
- CVE-2022-41091 KEV ransomware
- CVE-2022-44698 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-5950
- CVE-2024-27564
- CVE-2024-30051 KEV ransomware
- CVE-2024-4577 KEV ransomware
- CVE-2025-24813 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-68613 KEV
- CVE-2026-1731 KEV ransomware
- CVE-2026-20127 KEV
- CVE-2026-21236
- CVE-2027-11882
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
BazarBackdoor (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BazarBackdoor (Malware Family)
Show all 689 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IcedID (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BumbleBee (Malware Family)
-
Spam trends campaigns senior superlatives 2023
The original link failed its last check. Original publisher Detailsfor Spam trends campaigns senior superlatives 2023
-
Fork in the Ice- The New Era of IcedID
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fork in the Ice- The New Era of IcedID
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
VMware Brochure Template US Letter
The original link failed its last check. Original publisher Detailsfor VMware Brochure Template US Letter
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Monster Libra (TA551-Shathak) pushes IcedID (Bokbot) with Dark VNC and Cobalt Strike
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Monster Libra (TA551-Shathak) pushes IcedID (Bokbot) with Dark VNC and Cobalt Strike
-
Flight of the Bumblebee- Email Lures and File Sharing Services Lead to Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Flight of the Bumblebee- Email Lures and File Sharing Services Lead to Malware
-
IcedID (Bokbot) with Dark VNC and Cobalt Strike
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IcedID (Bokbot) with Dark VNC and Cobalt Strike
-
The original link failed its last check. Original publisher Detailsfor Qakbot report
-
SVCReady- A New Loader Gets Ready
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SVCReady- A New Loader Gets Ready
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Analysis- Trickbot
-
ITG23 Crypters Highlight Cooperation Between Cybercriminal Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ITG23 Crypters Highlight Cooperation Between Cybercriminal Groups
-
ITG23 crypters cooperation between cybercriminal groups
The original link failed its last check. Original publisher Detailsfor ITG23 crypters cooperation between cybercriminal groups
-
Detecting a MUMMY SPIDER campaign and Emotet infection
The original link failed its last check. Original publisher Detailsfor Detecting a MUMMY SPIDER campaign and Emotet infection
-
New Conversation Hijacking Campaign Delivering IcedID
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Conversation Hijacking Campaign Delivering IcedID
-
Conti Affiliate Exposed- New Domain Names, IP Addresses and Email Addresses Uncovered
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Conti Affiliate Exposed- New Domain Names, IP Addresses and Email Addresses Uncovered
-
The Ransomware Threat Landscape: What to Expect in 2022
The original link failed its last check. Original publisher Detailsfor The Ransomware Threat Landscape: What to Expect in 2022
-
Intelligence Insights- January 2022
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Intelligence Insights- January 2022
-
Emotet 2.0: Everything you need to know about the new Variant of the Banking Trojan - CloudSEK
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Emotet 2.0: Everything you need to know about the new Variant of the Banking Trojan - CloudSEK
-
TA551 (Shathak) pushes IcedID (Bokbot)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA551 (Shathak) pushes IcedID (Bokbot)
-
CONTInuing the Bazar Ransomware Story
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CONTInuing the Bazar Ransomware Story
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Intelligence Insights- November 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Intelligence Insights- November 2021
-
THREAT ANALYSIS REPORT- From Shatak Emails to the Conti Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor THREAT ANALYSIS REPORT- From Shatak Emails to the Conti Ransomware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2021-CTI-009
-
Digital banking fraud- how the Gozi malware works
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Digital banking fraud- how the Gozi malware works
-
TA551 Uses ‘SLIVER’ Red Team Tool in New Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA551 Uses ‘SLIVER’ Red Team Tool in New Activity
-
Case Study- From BazarLoader to Network Reconnaissance
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Case Study- From BazarLoader to Network Reconnaissance
-
Trickbot Rising — Gang Doubles Down on Infection Efforts to Amass Network Footholds
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Trickbot Rising — Gang Doubles Down on Infection Efforts to Amass Network Footholds
-
TrickBot gang doubles down enterprise infection
The original link failed its last check. Original publisher Detailsfor TrickBot gang doubles down enterprise infection
-
New Trickbot and BazarLoader campaigns use multiple delivery vectorsi
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Trickbot and BazarLoader campaigns use multiple delivery vectorsi
-
Threat hunting in large datasets by clustering security events
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat hunting in large datasets by clustering security events
-
Intelligence Insights- September 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Intelligence Insights- September 2021
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting TA551 domains
-
REvil-ution – A Persistent Ransomware Operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor REvil-ution – A Persistent Ransomware Operation
-
Shelob Moonlight – Spinning a Larger Web From IcedID to CONTI, a Trojan and Ransomware collaboration
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shelob Moonlight – Spinning a Larger Web From IcedID to CONTI, a Trojan and Ransomware collaboration
-
From Word to Lateral Movement in 1 Hour
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From Word to Lateral Movement in 1 Hour
-
Análisis campaña Emotet - Security Art Work
The original link failed its last check. Original publisher Detailsfor Análisis campaña Emotet - Security Art Work
-
The First Step- Initial Access Leads to Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The First Step- Initial Access Leads to Ransomware
-
An Encounter With TA551-Shathak
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An Encounter With TA551-Shathak
-
Let’s set ice on fire: Hunting and detecting IcedID infections
The original link failed its last check. Original publisher Detailsfor Let’s set ice on fire: Hunting and detecting IcedID infections
-
The original link failed its last check. Original publisher Detailsfor Botnet-update-Q1-2021.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The rise of QakBot
-
A Spike in BazarCall and IcedID Activity Detected in March
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Spike in BazarCall and IcedID Activity Detected in March
-
PaaS, or how hackers evade antivirus software
The original link failed its last check. Original publisher Detailsfor PaaS, or how hackers evade antivirus software
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2021-Threat-Detection-Report
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA551
-
The original link failed its last check. Original publisher Detailsfor Binary Defense
-
IcedID Banking Trojan Uses COVID-19 Pandemic to Lure New Victims
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IcedID Banking Trojan Uses COVID-19 Pandemic to Lure New Victims
-
So Unchill Melting UNC2198 ICEDID to Ransomware Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor So Unchill Melting UNC2198 ICEDID to Ransomware Operations
-
TA551- Email Attack Campaign Switches from Valak to IcedID
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA551- Email Attack Campaign Switches from Valak to IcedID
-
Expanding Range and Improving Speed- A RansomExx Approach
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Expanding Range and Improving Speed- A RansomExx Approach
-
Using similarity to expand context and map out threat campaigns
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Using similarity to expand context and map out threat campaigns
-
Quick Post: Spooky New PowerShell Obfuscation in Emotet Maldocs
The original link failed its last check. Original publisher Detailsfor Quick Post: Spooky New PowerShell Obfuscation in Emotet Maldocs
-
The original link failed its last check. Original publisher Detailsfor The Many Faces of Emotet
-
What's behind the increase in ransomware attacks this year?
The original link failed its last check. Original publisher Detailsfor What's behind the increase in ransomware attacks this year?
-
2020-q2-spamhaus-botnet-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor 2020-q2-spamhaus-botnet-threat-report.pdf
-
Evolution of Valak, from Its Beginnings to Mass Distribution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evolution of Valak, from Its Beginnings to Mass Distribution
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2020-CTI-008
-
vmwcb-report-modern-bank-heists-2020.pdf
The original link failed its last check. Original publisher Detailsfor vmwcb-report-modern-bank-heists-2020.pdf
-
The original link failed its last check. Original publisher Detailsfor Dissecting Emotet - Part 2
-
2020_State-of-Malware-Report.pdf
The original link failed its last check. Original publisher Detailsfor 2020_State-of-Malware-Report.pdf
-
The original link failed its last check. Original publisher Detailsfor Dissecting Emotet – Part 1
-
The original link failed its last check. Original publisher Detailsfor Forensics Report True Hedge
-
IcedID PNG -> PE parser and reconstructor for custom steganographic loader
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IcedID PNG -> PE parser and reconstructor for custom steganographic loader
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
The original link failed its last check. Original publisher Detailsfor News Archiv
-
Emotet Adds New Evasion Technique
The original link failed its last check. Original publisher Detailsfor Emotet Adds New Evasion Technique
-
The original link failed its last check. Original publisher Detailsfor SAS2019 Presentation
-
URSNIF, EMOTET, DRIDEX and BitPayme Linked by Loader
The original link failed its last check. Original publisher Detailsfor URSNIF, EMOTET, DRIDEX and BitPayme Linked by Loader
-
Examining Emotet’s Activities, Infrastructure
The original link failed its last check. Original publisher Detailsfor Examining Emotet’s Activities, Infrastructure
-
New EMOTET Hijacks a Windows API, Evades Sandbox
The original link failed its last check. Original publisher Detailsfor New EMOTET Hijacks a Windows API, Evades Sandbox
-
EMOTET Returns, Starts Spreading via Spam Botnet
The original link failed its last check. Original publisher Detailsfor EMOTET Returns, Starts Spreading via Spam Botnet
-
Qakbot Spreads like a Worm, Stings like a Trojan « Speaking of Security – The RSA Blog and Podcast
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Qakbot Spreads like a Worm, Stings like a Trojan « Speaking of Security – The RSA Blog and Podcast
-
Qakbot, Data Thief Unmasked: Part I
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Qakbot, Data Thief Unmasked: Part I
-
Qakbot Steals 2GB of Confidential Data per Week
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Qakbot Steals 2GB of Confidential Data per Week
-
Qakbot, Data Thief Unmasked: Part II
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Qakbot, Data Thief Unmasked: Part II
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor W32.Qakbot | Symantec
Newest first. Details opens the report in Explore.