TA459

🔴 High
Also known as: G0062, TA459

TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others. Proofpoint TA459 April 2017

🌍 Country China
Risk Level High
🧭 ATT&CK G0062

Introduction

TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others. Proofpoint TA459 April 2017

Activities and Tactics

Country of Origin: 🇨🇳 China

Risk Level: High

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • PlugX:
  • NetTraveler:
  • ZeroT:
  • PCrat:
  • Gh0st:
  • RoyalRoad RTF Weaponizer:

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: China Additional attribution information pending cataloguing.

References

[1] mitre-attack [3] Proofpoint TA459 April 2017 Axel F. (2017, April 27). APT Targets Financial Analysts with CVE-2017-0199. Retrieved February 15, 2018.