ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool Taurus Loader

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: Taurus Loader

NamesTaurus Loader
Taurus Builder
Taurus Builder Kit
CategoryMalware
TypeBotnet, Downloader
Description(Proofpoint) We use this name to describe a tool used to create malicious documents. We believe Taurus builder was purchased on underground crime forums. Notably, documents created with this builder use the CMSTP bypass.
Information<https://www.proofpoint.com/us/threat-insight/post/fake-jobs-campaigns-delivering-moreeggs-backdoor-fake-job-offers>
<https://medium.com/@quoscient/golden-chickens-uncovering-a-malware-as-a-service-maas-provider-and-two-new-threat-actors-using-61cf0cb87648>
<https://quointelligence.eu/2018/11/golden-chickens-uncovering-a-malware-as-a-service-maas-provider-and-two-new-threat-actors-using/>

Last change to this tool card: 10 July 2020

Download this tool card in JSON format

All groups using tool Taurus Loader

ChangedNameCountryObserved

APT groups

 Cobalt GroupRussia2016-Oct 2019X

Other groups

 Venom Spider, Golden ChickensRussia2017-Feb 2019 

2 groups listed (1 APT, 1 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key