Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: GOLD CABIN, Shathak
14
techniques
5
software
11,304
corpus matches
profile
TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns.
techniques
14 attributed · most-instrumented first
software
5 malware & tools attributed
Ursnif
S0386
Valak
S0476
IcedID
S0483
Sliver
S0633
QakBot
S0650
read this carefully
11,304 corpus matches is not attribution
That count is indicators which exhibit techniques TA551 is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+2 more techniques
showing 30 of 11,304
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.