THREAT_ACTOR · G0092
TA505
Also known as: TA505, Hive0065, Spandex Tempest, CHIMBORAZO
Profile
TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.
MITRE ATT&CK ↗Techniques
34 ATT&CK techniques attributed to this actor.
T1027.002 Software PackingT1027.010 Command ObfuscationT1027.013 Encrypted/Encoded FileT1055.001 Dynamic-link Library InjectionT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1059.007 JavaScriptT1069 Permission Groups DiscoveryT1071.001 Web ProtocolsT1078.002 Domain AccountsT1087.003 Email AccountT1105 Ingress Tool TransferT1106 Native APIT1112 Modify RegistryT1140 Deobfuscate/Decode Files or InformationT1204.001 Malicious LinkT1204.002 Malicious FileT1218.007 MsiexecT1218.011 Rundll32T1486 Data Encrypted for ImpactT1552.001 Credentials In FilesT1553.002 Code SigningT1553.005 Mark-of-the-Web BypassT1555.003 Credentials from Web BrowsersT1559.002 Dynamic Data ExchangeT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1568.001 Fast Flux DNST1583.001 DomainsT1588.001 MalwareT1588.002 ToolT1608.001 Upload MalwareT1685 Disable or Modify Tools
Software
16 malware/tools attributed to this actor.
MimikatzNetCobalt StrikePowerSploitTrickBotAzorultFlawedAmmyyServHelperFlawedGraceDridexGet2SDBbotBloodHoundAdFindClopAmadey
Related corpus activity
10,314 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to TA505.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,314.