Blog | G5 Cyber Security

TA505 Continues to Infect Networks With SDBbot RAT

IBM X-Force Incident Response and Intelligence Services (IRIS) identified attacks likely linked to Hive0065, also known as TA505. The group is a financially motivated cybercrime group that has been actively targeting various industries, including finance, retail and restaurants, since at least 2014. The TTPs used in these campaigns align with those of the group, specifically the spoofing of cloud storage websites to distribute malware files. The use of droppers containing embedded dynamic-link libraries (DLLs) is consistent with previous activity attributed to the group.”]

Source: https://securityintelligence.com/posts/ta505-continues-to-infect-networks-with-sdbbot-rat/

Exit mobile version