Also known as: APT28, Pawn Storm, Fancy Bear, Sednit, web skimming
Since January 2020, Proofpoint researchers have tracked an actor abusing Microsoft Office 365 (O365) third-party application (3PA) access, with suspected activity dating back to August 2019. The actor, known as TA2552, uses well-crafted Spanish language lures that leverage a narrow range of themes and brands. The lures entice users to click a link in the message, taking them to the legitimate Microsoft third-party apps consent page. There they are prompted to grant a third-party application read-only user permissions to their O365 account via OAuth2 or other token-based authorization methods. TA2552 seeks access to specific account resources like the user’s contacts and mail. Requesting read-only permissions for such account resources could be used to conduct account reconnaissance, silently steal data, or to intercept password reset messages from other accounts such as those at financial institutions. While organizations with global presence have received messages from this group, they appear to choose recipients who are likely Spanish speakers.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TA2552 is a threat actor exploiting Microsoft Office 365 third-party application access since January 2020. They use Spanish-language phishing lures to deceive users into granting unauthorized access to their O365 accounts, enabling reconnaissance and data theft. This actor targets individuals likely fluent in Spanish, leveraging language-specific tactics to compromise user credentials and intercept sensitive communications.
Goals & Targeting
TA2552's strategic objectives appear centered on gaining unauthorized access to Microsoft Office 365 accounts for intelligence gathering and potential data exfiltration. Their targeting profile focuses on users who are Spanish speakers, likely due to the effectiveness of language-based phishing in reducing victim suspicion. The group's narrow focus on O365 third-party application abuse suggests they aim to operate under the radar while maximizing access to sensitive corporate and personal communications.
Enhanced Description
TA2552 has been observed since mid-2019, with activity accelerating in early 2020. The group specializes in abusing Microsoft Office 365 third-party applications (3PA) by leveraging OAuth2 authorization flows. Their phishing campaigns employ well-crafted Spanish-language messages that trick recipients into visiting legitimate consent pages for third-party apps. This access enables TA2552 to harvest user credentials, conduct account reconnaissance, and potentially intercept sensitive communications such as password reset emails from financial institutions. The group's targeting appears to focus on individuals who are Spanish speakers, possibly reflecting an effort to exploit language-specific trust and reduce suspicion. While their operations have a global footprint, the primary focus appears to be on users who interact with O365 accounts in a manner that aligns with professional or linguistic ties to Spain.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA2552 has demonstrated persistence and operational security in their campaigns. Their targeting of Spanish-speaking individuals across various global sectors suggests a broad but focused approach, likely aiming for maximal access while minimizing detection. The use of legitimate OAuth consent flows makes their activities harder to detect compared to traditional malware-based attacks. Notable past operations include multiple waves of phishing campaigns tracked by Proofpoint since August 2019, with a steady increase in activity through early 2020.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in TA2552's activity is high, based on tracked campaigns and clear patterns of behavior. The actor’s targeting methods and TTPs are well-documented by Proofpoint. However, gaps remain in understanding their long-term strategic goals beyond immediate account compromise, as well as the full extent of their operational infrastructure. Additional intelligence sharing could help better characterize these aspects.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
40
Tools
0
Campaigns
39
IOCs
0
Observed Data
1
Tactics