From URSNIF IoCs to Software Spoofing: Using DNS Intel to Connect the Dots
Financially motivated threat actors called "TA544" were first detected in 2017. TA544 is known for high-volume campaigns, sending hundreds of thousands of malicious messages daily.
Source: circleid.com