Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TA2552

Also known as: APT28, Pawn Storm, Fancy Bear, Sednit, web skimming

Description

Since January 2020, Proofpoint researchers have tracked an actor abusing Microsoft Office 365 (O365) third-party application (3PA) access, with suspected activity dating back to August 2019. The actor, known as TA2552, uses well-crafted Spanish language lures that leverage a narrow range of themes and brands. The lures entice users to click a link in the message, taking them to the legitimate Microsoft third-party apps consent page. There they are prompted to grant a third-party application read-only user permissions to their O365 account via OAuth2 or other token-based authorization methods. TA2552 seeks access to specific account resources like the user’s contacts and mail. Requesting read-only permissions for such account resources could be used to conduct account reconnaissance, silently steal data, or to intercept password reset messages from other accounts such as those at financial institutions. While organizations with global presence have received messages from this group, they appear to choose recipients who are likely Spanish speakers.

Goals & Targeting

Targeted Sectors

Government
Non profit
Think tank
Defense
Energy

Targeted Countries / Regions

IR
IL
SA
US

AI Analysis

· 1 week ago

Executive Summary

TA2552 is a threat actor exploiting Microsoft Office 365 third-party application access since January 2020. They use Spanish-language phishing lures to deceive users into granting unauthorized access to their O365 accounts, enabling reconnaissance and data theft. This actor targets individuals likely fluent in Spanish, leveraging language-specific tactics to compromise user credentials and intercept sensitive communications.

Goals & Targeting

TA2552's strategic objectives appear centered on gaining unauthorized access to Microsoft Office 365 accounts for intelligence gathering and potential data exfiltration. Their targeting profile focuses on users who are Spanish speakers, likely due to the effectiveness of language-based phishing in reducing victim suspicion. The group's narrow focus on O365 third-party application abuse suggests they aim to operate under the radar while maximizing access to sensitive corporate and personal communications.

Enhanced Description

TA2552 has been observed since mid-2019, with activity accelerating in early 2020. The group specializes in abusing Microsoft Office 365 third-party applications (3PA) by leveraging OAuth2 authorization flows. Their phishing campaigns employ well-crafted Spanish-language messages that trick recipients into visiting legitimate consent pages for third-party apps. This access enables TA2552 to harvest user credentials, conduct account reconnaissance, and potentially intercept sensitive communications such as password reset emails from financial institutions. The group's targeting appears to focus on individuals who are Spanish speakers, possibly reflecting an effort to exploit language-specific trust and reduce suspicion. While their operations have a global footprint, the primary focus appears to be on users who interact with O365 accounts in a manner that aligns with professional or linguistic ties to Spain.

Key Capabilities

  • OAuth2-based phishing
  • Third-party application abuse
  • Language-specific spear-phishing campaigns
  • Credential harvesting via social engineering

MITRE ATT&CK Tactics

Credential Access
Collection
Reconnaissance

ATT&CK Techniques

T1098.003 - Valid Accounts: Office365 Account Access
T1134 - Social Engineering Phishing via Email
T1059 - External Remote Console Access
T1566.002 - Account Access Removal

Software / Tooling

Custom phishing templates
Third-party O365 application interfaces
Social engineering tools to craft Spanish language lures

Campaigns & Victims

TA2552 has demonstrated persistence and operational security in their campaigns. Their targeting of Spanish-speaking individuals across various global sectors suggests a broad but focused approach, likely aiming for maximal access while minimizing detection. The use of legitimate OAuth consent flows makes their activities harder to detect compared to traditional malware-based attacks. Notable past operations include multiple waves of phishing campaigns tracked by Proofpoint since August 2019, with a steady increase in activity through early 2020.

IOC Patterns

  • Phishing emails sent from legitimate domains but containing malicious links
  • Redirects to Microsoft O365 third-party app consent pages
  • Unusual OAuth token grant requests for read-only user permissions
  • Scheduled spikes in login attempts or application access attempts

Recommended Actions

  • Implement multi-factor authentication (MFA) for Office 365 accounts
  • Monitor login activity, especially during off-hours
  • Educate users about phishing tactics, particularly language-based spear-phishing campaigns
  • Use email filtering to detect and block suspicious emails
  • Conduct regular audits of third-party app permissions in O365

Suggested Tags

Phishing
Spear Phishing
Office 365 Abuse
Financial Espionage
Language-based TTP

Confidence Assessment

Confidence in TA2552's activity is high, based on tracked campaigns and clear patterns of behavior. The actor’s targeting methods and TTPs are well-documented by Proofpoint. However, gaps remain in understanding their long-term strategic goals beyond immediate account compromise, as well as the full extent of their operational infrastructure. Additional intelligence sharing could help better characterize these aspects.

ATT&CK Techniques

Impact
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. pmc.ncbi.nlm.nih.gov — Cited by web research for: Curl
  2. apt.etda.or.th — Cited by web research for: Dark
  3. www.proofpoint.com — Cited by web research for: Leverage

Intel Summary

1

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

1

Tactics

Tags

Financial Targeting
Supply Chain Attack
Phishing
Spear Phishing
Office 365 Abuse
Financial Espionage
Language-based TTP

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.