G0127: TA551
Security context for executives and security teams
G0127: TA551 describes [TA551](https://attack.mitre.org/groups/G0127) is a financially-motivated threat group that has been active since at least 2018. (Citation: Secureworks GOLD CABIN) The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns. (Citation: Unit 42 TA551 Jan 2021)
Executive priority
G0127: TA551 is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0127: TA551 by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0127: TA551 appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
TA551
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1218.010 | Regsvr32Sub-technique | |
| Enterprise | T1589.002 | Email AddressesSub-technique | |
| Enterprise | T1204.002 | Malicious FileSub-technique | |
| Enterprise | T1218.011 | Rundll32Sub-technique | |
| Enterprise | T1027.003 | SteganographySub-technique | |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | |
| Enterprise | T1132.001 | Standard EncodingSub-technique | |
| Enterprise | T1568.002 | Domain Generation AlgorithmsSub-technique | |
| Enterprise | T1027.010 | Command ObfuscationSub-technique | |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | |
| Enterprise | T1105 | Ingress Tool Transfer | |
| Enterprise | T1218.005 | MshtaSub-technique | |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | |
| Enterprise | T1036 | Masquerading |
Groups, software, and campaigns
S0650: QakBot
S0483: IcedID
S0476: Valak
S0633: Sliver
S0386: Ursnif
Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links.[1][2] Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.[3]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.2 | Current bundle | a16b7facd520… | ||
| 19.1 | 1.2 | Older bundle | 2801977a3115… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Secureworks GOLD CABIN
Secureworks. (n.d.). GOLD CABIN Threat Profile. Retrieved March 17, 2021.
Open source URL - [2]Unit 42 TA551 Jan 2021
Duncan, B. (2021, January 7). TA551: Email Attack Campaign Switches from Valak to IcedID. Retrieved March 17, 2021.
Open source URL - [3]Unit 42 Valak July 2020
Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.
Open source URL - [4]GOLD CABIN
(Citation: Secureworks GOLD CABIN)
- [5]Shathak
(Citation: Unit 42 Valak July 2020)(Citation: Unit 42 TA551 Jan 2021)
- [6]mitre-attackG0127Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
