TA866 New Financially-Motivated Threat Actor Targeting US and Germany Organizations

Threat Level – Red | Vulnerability Report
Download PDF

A new financially motivated threat actor named TA866 has been active since October 2022 and targets organizations in the United States and Germany. The attack chain starts with a malicious email containing an attachment or URL, leading to the installation of WasabiSeed and Screenshotter. TA866 is an organized actor that is able to perform attacks at scale based on their custom tools and ability to purchase tools and services from other vendors.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox