July 9, 2019 By David Bisson 2 min read

Security researchers observed the TA505 threat group delivering two new payloads, the Gelup malware tool and the FlowerPippi backdoor, via spam campaigns.

Trend Micro detected the spam campaign on June 20 targeting users in Japan, the Philippines and Argentina. The attackers crafted their emails to deliver DOC and XLS files containing malicious Visual Basic for Applications (VBA) macros. These scripts, in turn, downloaded FlowerPippi malware, which functioned as a backdoor on infected machines.

That’s not all Trend Micro found. In their analysis of FlowerPippi, the researchers discovered that the spam campaign pushed out another new malware tool called Gelup. Written in C++ and designed to function as a downloader of other malware, Gelup stood out for its obfuscation techniques. Gelup can also bypass User Account Control (UAC) by mocking trusted directories, abusing auto-elevated executables and using the Dynamic Link Library (DLL) side-loading technique.

A Busy Year for the TA505 Threat Group

Gelup — detected by Proofpoint as AndroMut — and FlowerPippi are just some of TA505’s latest innovations. In January, Proofpoint observed the threat group using two new malware tools — the ServHelper backdoor and the FlawedGrace remote access Trojan (RAT) — to target banks, retail businesses and restaurants.

Just a few months later, Cybereason detected a campaign launched by the group that used living-off-the-land binaries (LOLBins) and legitimate Windows operating system (OS) processes to deliver ServHelper.

Around that same time, Trend Micro discovered a campaign in which the threat actor targeted users in Chile and Mexico with samples of the FlawedAmmyy RAT and RMS RAT malware families.

Embrace a Layered Approach to Spam Detection

To help defend against TA505 and its ever-expanding arsenal of malware, start by creating a layered approach to email security that consists of mail scanning, antispam filters and security awareness training. Security teams should also use ahead-of-threat detection to block potentially malicious domains before they become active in phishing attacks and other campaigns.

More from

Bypassing Windows Defender Application Control with Loki C2

10 min read - Windows Defender Application Control (WDAC) is a security solution that restricts execution to trusted software. Since it is classified as a security boundary, Microsoft offers bug bounty payouts for qualifying bypasses, making it an active and competitive field of research.Typical outcomes of a WDAC bypass bug bounty submission:Bypass is fixed; possible bounty awardedBypass is not fixed but instead "mitigated" by being added to the WDAC recommended block list. Likely no bounty awarded but honorable mention is typically givenBypass is not…

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today