TA570
Also reported as DEV-0450. Linked to Russia by two sources.
Reports per quarter
CVEs named in reports
- CVE-2017-11882 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
Show all 17 CVEs Show fewer
- CVE-2021-31207 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2024-30051 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor QakBot (Malware Family)
-
Spam trends campaigns senior superlatives 2023
The original link failed its last check. Original publisher Detailsfor Spam trends campaigns senior superlatives 2023
Show all 16 reports Show fewer
-
Qakbot Evolves to OneNote Malware Distribution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Qakbot Evolves to OneNote Malware Distribution
-
TA570 Qakbot (Qbot) tries CVE-2022-30190 (Follina) exploit (ms-msdt)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA570 Qakbot (Qbot) tries CVE-2022-30190 (Follina) exploit (ms-msdt)
-
The First Step- Initial Access Leads to Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The First Step- Initial Access Leads to Ransomware
Newest first. Details opens the report in Explore.