404 TDS and TA584's Changing Initial Access
See how an error response can become a redirect and how one actor changed TDS choices over time.
In this lesson, you will learn to:
- Explain the 404/meta-refresh mechanism.
- Compare actor use of 404 TDS across dated campaigns.
404 TDS and TA584’s Changing Initial Access
Connects 404 TDS to TA866 and TA584 reporting, explains meta-refresh routing, and uses dated IP and registration evidence without turning old indicators into timeless truth.
The error page contains the next route
404 TDS was named for a mechanism observed in early campaigns: the server returned an HTTP 404 Not Found status while the response body contained a meta-refresh instruction that directed the browser onward. A tool or analyst that records only the status code can miss the navigation. Later behavior may vary, so the name should not be treated as a guarantee that every response still uses the same technique.
Inspect permitted response bodies, HTML refresh directives, scripts, and subsequent browser events. Preserve both the status and redirect sequence. A 404 response can be a filter result, decoy, error, or routing step; context decides. This case demonstrates a broader lesson: protocol metadata and content can tell different parts of the story.
TA866 shows shared-service infrastructure
In 2022 reporting, Proofpoint observed TA866 campaign links leading to 404 TDS before further filtering and malware delivery. The reported TDS set used many random five-character paths, around 20 domains registered on the day of the campaign, and infrastructure observed at 178.20.45[.]197 and 185.180.199[.]229. Those are historical, defanged observations—not claims about current ownership or behavior.
Proofpoint assessed that 404 TDS was likely shared or sold because it appeared in unrelated phishing and malware campaigns. That supports a service relationship hypothesis, not one common actor. Later Proofpoint reporting also connected 404 TDS with TA571 campaigns delivering IcedID variants. Build the relationship table by campaign and date rather than assigning every 404 TDS observation to TA866.
TA584 made 404 TDS prominent in 2025
Proofpoint’s January 2026 analysis said TA584 had commonly used Cookie Reloaded or Prometheus TDS in prior years, occasionally switched to Keitaro, and most frequently used 404 TDS as its primary filter in 2025. The actor also varied lure URLs and campaign infrastructure. This churn makes a permanent rule for one domain or platform insufficient.
Detect the sequence: delivery message or collaboration lure, URL or intermediary service, short redirect burst, filtering response, fake page or file host, download, and endpoint behavior. Add time-bounded indicators for urgent protection, but preserve behavioral analytics that survive a platform switch. The actor’s choice of TDS is a campaign feature, not its identity.
Resources
- Proofpoint: TA866 and 404 TDS — Review the original infrastructure, filtering, and campaign observations for the Screenshotter and WasabiSeed chain.
- Proofpoint: TA584 in 2025 — Use the January 2026 comparison of Cookie Reloaded, Keitaro, and 404 TDS choices.