TA505 malware samples are being detected after a short break, as this threat group had been highly active since late June until late September. Threat Actors make use of packers when distributing their malware as they remain an effective way to evade detection and to make them more difficult to analyze. Packed samples are found being distributed. TA505 is a prolific cybercriminal group known for its attacks against multiple financial institutions and retail companies using malicious spam campaigns and different malware. In this latest campaign, samples of AZORult information Stealer have been detected. Malware is usually deployed by this threat actor via Office Template Macros leading to the malware. This also allows threat actors to gain access to the compromised network, providing opportunities to steal financial data or install ransomware. TA505 aka EvilCorp is found consistently targeting financial institutions around the world.