TA459

G0062

Threat group.View on attack.mitre.org

About this group

TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1059.001
PowerShell

TA459 has used PowerShell for execution of a payload.

T1059.005
Visual Basic

TA459 has a VBScript for execution.

T1203
Exploitation for Client Execution

TA459 has exploited Microsoft Word vulnerability CVE-2017-0199 for execution.

T1204.002
Malicious File

TA459 has attempted to get victims to open malicious Microsoft Word attachment sent via spearphishing.

T1566.001
Spearphishing Attachment

TA459 has targeted victims using spearphishing emails with malicious Microsoft Word attachments.

Software4

Campaigns0

None recorded.

References1

  1. Proofpoint TA459 April 2017 Open source
    Axel F. (2017, April 27). APT Targets Financial Analysts with CVE-2017-0199. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.