Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TA2719

Description

In late March 2020, Proofpoint researchers began tracking a new actor with a penchant for using NanoCore and later AsyncRAT, popular commodity remote access trojans (RATs). Dubbed TA2719 by Proofpoint, the actor uses localized lures with colorful images that impersonate local banks, law enforcement, and shipping services. Proofpoint has observed this actor send low volume campaigns to recipients in Austria, Chile, Greece, Hungary, Italy, North Macedonia, Netherlands, Spain, Sweden, Taiwan, United States, and Uruguay.

AI Analysis

· 1 week ago

Executive Summary

TA2719 is a cyber threat actor identified by Proofpoint in late March 2020, known for leveraging commodity remote access trojans (RATs) such as NanoCore and AsyncRAT. The group employs localized phishing campaigns with malicious emails impersonating local banks, law enforcement, and shipping services, targeting individuals across multiple countries including Austria, Chile, Greece, Hungary, Italy, North Macedonia, Netherlands, Spain, Sweden, Taiwan, United States, and Uruguay. Despite its use of commonly available tools, TA2719 demonstrates a sophisticated approach to campaign operations, focusing on low-volume attacks that may be designed to evade detection while achieving financial gain or data theft objectives.

Goals & Targeting

TA2719's strategic objectives appear to be primarily financial, as evidenced by their use of malicious tools like RATs, which are often associated with data theft and fraudulent activities. The group's targeting of individuals in multiple countries suggests a global operational scope, possibly aiming to maximize their reach and opportunities for gain. Their focus on impersonating local institutions may indicate an attempt to exploit trust in familiar brands or services to increase the success rate of their campaigns. The sectors targeted by TA2719—banking, law enforcement, shipping—suggest a desire to access sensitive data or disrupt specific industries. Typical victims include individuals in both private and corporate settings who receive these phishing emails, making organizations across all sectors potentially at risk.

Enhanced Description

TA2719 is a cyber threat actor that Proofpoint began tracking in late March 2020. The group primarily utilizes commodity remote access trojans (RATs) such as NanoCore and AsyncRAT to carry out its activities. TA2719's operations are characterized by localized phishing campaigns, where the actors send emails with colorful images designed to impersonate local banks, law enforcement agencies, or shipping services. These campaigns are likely intended to exploit trust in local institutions to trick recipients into opening malicious attachments or clicking on suspicious links. The group has been observed targeting individuals across a wide range of countries, including Austria, Chile, Greece, Hungary, Italy, North Macedonia, Netherlands, Spain, Sweden, Taiwan, United States, and Uruguay. Despite the use of relatively common tools like RATs, TA2719's operational approach appears to be carefully crafted to remain under the radar, with low-volume campaigns that may indicate a focus on quality over quantity. The group's targeting of multiple geographic regions suggests a potential interest in geographically diverse victimology, possibly to maximize reach or avoid detection.

Key Capabilities

  • Use of commodity remote access trojans (RATs) such as NanoCore and AsyncRAT
  • Localized phishing campaigns with malicious email attachments
  • Impersonation of local banks, law enforcement, and shipping services
  • Low-volume targeting across multiple countries
  • Sophisticated campaign operations to avoid detection

MITRE ATT&CK Tactics

Email Compromise
Credential Access
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1057
T1566.003
T1212.001
T1046
T1398

Software / Tooling

NanoCore RAT
AsyncRAT
Custom phishing email templates

Campaigns & Victims

TA2719's campaign patterns involve low-volume, geographically diverse attacks that may be designed to evade detection. The group's focus on localized lures suggests an understanding of cultural and regional factors that could enhance the success rate of their campaigns. Despite the use of common tools like RATs, TA2719 demonstrates a level of operational maturity consistent with more advanced actors, particularly in their targeting and delivery mechanisms. Notable operations include phishing campaigns impersonating local banks and law enforcement agencies across multiple countries, indicating a broad and flexible approach to victim selection.

IOC Patterns

  • Phishing emails containing malicious Office attachments
  • Network traffic indicative of远程访问木马 (RAT)通信
  • Spear-phishing with localized/lured content
  • Use of commodity RATs like NanoCore and AsyncRAT
  • Potential C2 infrastructure using compromised or legitimate services

Recommended Actions

  • Implement advanced email filtering to detect and block phishing emails with malicious attachments or links.
  • Monitor for unusual network activity indicative of RAT communication patterns.
  • Educate employees about spear-phishing tactics, especially those involving local institutions.
  • Apply regular updates and patches to systems to mitigate known vulnerabilities exploited by RATs.
  • Use multi-factor authentication (MFA) to secure sensitive accounts and reduce the impact of credential theft.

Suggested Tags

Cybercrime
Financially motivated
Phishing
RAT
Geographically diverse

Confidence Assessment

Moderate confidence in TA2719's profile based on available data. While the actor's use of commodity tools and identified TTPs provides a clear picture of their capabilities, specific details about their long-term goals, exact campaign history beyond what is reported by Proofpoint, and operational infrastructure remain unclear. Additional intelligence sharing and analysis would help refine understanding of this threat group.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
Cybercrime
Financially motivated
Phishing
RAT
Geographically diverse

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.