Module 2: Named Services and Campaigns

404 TDS and TA584's Changing Initial Access

See how an error response can become a redirect and how one actor changed TDS choices over time.

In this lesson, you will learn to:

  • Explain the 404/meta-refresh mechanism.
  • Compare actor use of 404 TDS across dated campaigns.

404 TDS and TA584’s Changing Initial Access

Connects 404 TDS to TA866 and TA584 reporting, explains meta-refresh routing, and uses dated IP and registration evidence without turning old indicators into timeless truth.

The error page contains the next route

404 TDS was named for a mechanism observed in early campaigns: the server returned an HTTP 404 Not Found status while the response body contained a meta-refresh instruction that directed the browser onward. A tool or analyst that records only the status code can miss the navigation. Later behavior may vary, so the name should not be treated as a guarantee that every response still uses the same technique.

Inspect permitted response bodies, HTML refresh directives, scripts, and subsequent browser events. Preserve both the status and redirect sequence. A 404 response can be a filter result, decoy, error, or routing step; context decides. This case demonstrates a broader lesson: protocol metadata and content can tell different parts of the story.

TA866 shows shared-service infrastructure

In 2022 reporting, Proofpoint observed TA866 campaign links leading to 404 TDS before further filtering and malware delivery. The reported TDS set used many random five-character paths, around 20 domains registered on the day of the campaign, and infrastructure observed at 178.20.45[.]197 and 185.180.199[.]229. Those are historical, defanged observations—not claims about current ownership or behavior.

Proofpoint assessed that 404 TDS was likely shared or sold because it appeared in unrelated phishing and malware campaigns. That supports a service relationship hypothesis, not one common actor. Later Proofpoint reporting also connected 404 TDS with TA571 campaigns delivering IcedID variants. Build the relationship table by campaign and date rather than assigning every 404 TDS observation to TA866.

TA584 made 404 TDS prominent in 2025

Proofpoint’s January 2026 analysis said TA584 had commonly used Cookie Reloaded or Prometheus TDS in prior years, occasionally switched to Keitaro, and most frequently used 404 TDS as its primary filter in 2025. The actor also varied lure URLs and campaign infrastructure. This churn makes a permanent rule for one domain or platform insufficient.

Detect the sequence: delivery message or collaboration lure, URL or intermediary service, short redirect burst, filtering response, fake page or file host, download, and endpoint behavior. Add time-bounded indicators for urgent protection, but preserve behavioral analytics that survive a platform switch. The actor’s choice of TDS is a campaign feature, not its identity.

Resources