TA585 Deploys Novel Web-Injection to Deliver MonsterV2 Malware on Windows
## Cybersecurity Update: TA585 and MonsterV2 Malware
Cybersecurity Update: TA585 and MonsterV2 Malware
As cyber threats continue to evolve, the emergence of new adversaries such as threat group TA585 presents significant challenges. This group is noted for employing advanced malware campaigns, particularly through the use of the MonsterV2 malware.
TA585 is distinguished by its self-reliant operational strategy, managing each stage of its attack chain independently. The group utilizes its own infrastructure to deploy malware like MonsterV2, a remote access trojan (RAT) and data stealer. This malware was first identified in February 2025 and has gained attention for its comprehensive feature set and high cost, making it appealing to well-funded cyber actors.
MonsterV2 is offered as malware-as-a-service (MaaS), with capabilities including data exfiltration, remote desktop access, command execution, and dual functionality as a loader and info-stealer. Pricing for MonsterV2 starts at $800 per month, with enterprise options reaching $2,000.
TA585's campaigns were first observed in February 2025, featuring phishing attacks that mimic government notifications. These campaigns use PDFs that redirect users to malicious web pages employing the ClickFix technique. This method prompts users to execute a PowerShell command manually, bypassing traditional antivirus detections.
As cyber threats continue to evolve, the emergence of new adversaries such as threat group TA585 presents significant challenges.
In April and May 2025, the group expanded operations with JavaScript web injects on compromised sites, selectively targeting users with fake CAPTCHAs that lead to the installation of the MonsterV2 payload. TA585’s infrastructure ensures that only genuine users, not bots or security researchers, receive the malware.
MonsterV2 performs extensive system reconnaissance and data exfiltration, with capabilities for privilege escalation and secondary payload delivery. The malware uses encrypted communication and configuration files via the ChaCha20 algorithm, making detection difficult.
MonsterV2 avoids targeting systems in certain CIS countries and employs anti-debug and anti-sandbox techniques. Persistence is managed through autorun and mutex creation.
TA585's comprehensive control over its attack ecosystem, combined with its sophisticated tactics, underscores the need for vigilant monitoring and adaptive cybersecurity measures. Organizations are advised to educate users on the risks of the ClickFix technique and limit non-administrative PowerShell use on Windows platforms.
Based on reporting by GBHackers.
