TA505
MITRE: G0092TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.
Alternate names
Hive0065, Spandex Tempest, CHIMBORAZO,
The advanced persistent threat (APT) group known as TA505 is an Iranian hacking organization that has been active since at least 2014, targeting government agencies and organizations in various countries including the United States, Israel, Saudi Arabia, and Qatar. They are known for their sophisticated tactics such as spear-phishing emails, watering hole attacks, and exploiting vulnerabilities to gain access to sensitive information. TA505 has been linked to several high-profile cyberattacks including the 2016 attack on Saudi Aramco's computer systems that resulted in significant damage estimated at $30 billion USD.
Techniques, tactics and practices:
The techniques, tactics, and practices used by TA505 include spear-phishing emails that contain malicious attachments or links to compromised websites. They also use watering hole attacks where they exploit vulnerabilities in popular websites frequented by their target audience to deliver malware. Additionally, the group has been known to exploit software and hardware vulnerabilities such as those found in Microsoft Office and Adobe Flash Player. TA505 is considered a highly sophisticated APT due to its use of advanced techniques like these.
Alternate Group Names
ATK103, CHIMBORAZO, Dudear, G0092, GOLD TAHOE, GRACEFUL SPIDER, Hive0065, SectorJ04, SectorJ04 Group, Spandex Tempest,
Alternative Names
CHIMBORAZO, SectorJ04, Dudear, Spandex Tempest, ATK103, Hive0065, G0092,
