Avis de sécurité

Menaces et incidents


? Development of the activity of the TA505 cybercriminal group (21 septembre 2020)

Publié le 21 septembre 2020 02:00

French version: ????????

 

The intrusion set TA505 has been active since at least 2014 when it initially stole financial information through the use of Dridex and mass distributed ransomwares. It evolved and now conducts phishing campaigns against a wide range of businesses. Its goal is now to resell the access it gained to the information system of its victims or to encrypt it entirely to ask for a ransom.

This report provides a synthetis of ANSSI's knowledge on TA505 to help increasing protections against it.

Indicators of compromise are available on the page CERTFR-2020-IOC-004.

 

DOWNLOAD THE REPORT

LIENS ASSOCIES


Inscrivez-vous à la newsletter CSIRT pour recevoir périodiquement les publications

Contact

contact@csirt-universitaire.org
+221 78 601 64 64
BP: XXX - Sénégal