LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0092: TA505

TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.CitationProofpoint TA505 Sep 2017CitationProofpoint TA505 June 2018CitationProofpoint TA505 Jan 2019CitationNCC Group TA505CitationKorean FSI TA505 2020

EnterpriseG0092GroupObject v3.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

TA505 matters because MITRE describes it as a long-running cyber criminal group known for frequently changing malware, influencing criminal malware distribution, and ransomware campaigns involving Clop. For leaders, the key issue is not a single indicator list; it is whether the organization can detect and respond when tooling changes across downloaders, RATs, credential theft, Active Directory discovery, and ransomware-related activity.

Executive priority

Prioritize TA505 as a readiness test for ransomware resilience, identity security, and SOC adaptability. Executives should ask whether endpoint, scripting, credential, and Active Directory telemetry are retained and usable during an incident; whether incident response can handle fast-changing malware families; and whether backup, containment, and evidence-collection processes are proven before ransomware pressure occurs.

Technical view

ATT&CK provides no official detection text for this group, so coverage should be validated through the related software and techniques. The relationship set is strongly Windows-oriented and includes Mimikatz, Net, Cobalt Strike, PowerSploit, TrickBot, Azorult, FlawedAmmyy, ServHelper, FlawedGrace, Dridex, Get2, SDBbot, BloodHound, AdFind, Clop, and Amadey. Related techniques include PowerShell, Windows Command Shell, Visual Basic, JavaScript, software packing, command obfuscation, encrypted or encoded files, and DLL injection. SOC teams should test visibility across script execution, command lines, process lineage, memory/process behavior, AD enumeration, credential-access tooling, downloader/backdoor activity, and ransomware-family alert handling.

Likely telemetry

  • Endpoint process creation and command-line telemetry, especially PowerShell, cmd, Visual Basic, and JavaScript execution
  • PowerShell script block, module, and operational logs where available
  • Windows security and endpoint events related to credential dumping tools and suspicious access to credential material
  • Active Directory query and enumeration evidence associated with tools such as BloodHound and AdFind
  • Network connections and proxy/DNS records for downloader, RAT, and backdoor communications

Detection direction

  • Because MITRE supplies no official detection guidance, base validation on relationship-driven behaviors rather than group name matching.
  • Tune for suspicious combinations: scripting or shell execution followed by downloader/RAT behavior, AD discovery, credential tooling, lateral-use utilities, or ransomware-like file activity.
  • Account for obfuscation: packed files, encoded content, and obfuscated commands can reduce signature-only effectiveness.
  • Separate legitimate administration from abuse of tools such as Net, PowerShell, Cobalt Strike-like behavior, BloodHound, and AdFind by using user role, host role, execution context, parent process, timing, and change-ticket context.
  • Validate Windows endpoint depth first, since most related software and several techniques are Windows-focused, while noting some related techniques and Cobalt Strike list Linux/macOS as possible platforms.

Mitigation priorities

  • Strengthen identity and Active Directory hygiene first: reduce excessive privileges, monitor administrative activity, and prepare containment procedures for credential compromise.
  • Harden scripting and command execution controls where operationally feasible, including PowerShell governance and logging.
  • Improve endpoint prevention and detection for packed/encoded files, suspicious DLL injection, credential dumping, and unauthorized remote access tooling.
  • Prepare ransomware resilience: tested backups, restore procedures, segmentation, and incident decision playbooks tied to Clop-related readiness without assuming current exposure.
  • Maintain threat intelligence updates for the listed aliases and related malware/tools, but avoid relying only on static indicators because the group is described as frequently changing malware.
Additional notes and limits

Aliases supplied by ATT&CK include TA505, Hive0065, Spandex Tempest, and CHIMBORAZO. The most useful defensive framing is a coverage assessment across related tooling and behaviors, not a claim that any one indicator proves TA505 activity. Relationship context highlights credential dumping, AD reconnaissance, scripting, obfuscation, remote access tools, downloaders, backdoors, and ransomware.

Platforms and tactics are not specified on the intrusion-set object itself, and official detection is not provided. Platform and behavior guidance here is inferred only from supplied related software and technique fields. Local telemetry, asset criticality, business process exposure, and confirmed incident evidence are required before assessing organizational exposure or attribution.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

TA505

TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.CitationProofpoint TA505 Sep 2017CitationProofpoint TA505 June 2018CitationProofpoint TA505 Jan 2019CitationNCC Group TA505CitationKorean FSI TA505 2020

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.0
Created
Modified
Raw hash
7fb924ac7a47f8df...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.