Threat group.View on attack.mitre.org
TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.
| Technique | Procedure example |
|---|---|
| T1059.001 PowerShell |
TA459 has used PowerShell for execution of a payload. |
| T1059.005 Visual Basic |
TA459 has a VBScript for execution. |
| T1203 Exploitation for Client Execution |
TA459 has exploited Microsoft Word vulnerability CVE-2017-0199 for execution. |
| T1204.002 Malicious File |
TA459 has attempted to get victims to open malicious Microsoft Word attachment sent via spearphishing. |
| T1566.001 Spearphishing Attachment |
TA459 has targeted victims using spearphishing emails with malicious Microsoft Word attachments. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.