In late March 2020, Proofpoint researchers began tracking a new actor with a penchant for using NanoCore and later AsyncRAT, popular commodity remote access trojans (RATs). Dubbed TA2719 by Proofpoint, the actor uses localized lures with colorful images that impersonate local banks, law enforcement, and shipping services. Proofpoint has observed this actor send low volume campaigns to recipients in Austria, Chile, Greece, Hungary, Italy, North Macedonia, Netherlands, Spain, Sweden, Taiwan, United States, and Uruguay.
Executive Summary
TA2719 is a cyber threat actor identified by Proofpoint in late March 2020, known for leveraging commodity remote access trojans (RATs) such as NanoCore and AsyncRAT. The group employs localized phishing campaigns with malicious emails impersonating local banks, law enforcement, and shipping services, targeting individuals across multiple countries including Austria, Chile, Greece, Hungary, Italy, North Macedonia, Netherlands, Spain, Sweden, Taiwan, United States, and Uruguay. Despite its use of commonly available tools, TA2719 demonstrates a sophisticated approach to campaign operations, focusing on low-volume attacks that may be designed to evade detection while achieving financial gain or data theft objectives.
Goals & Targeting
TA2719's strategic objectives appear to be primarily financial, as evidenced by their use of malicious tools like RATs, which are often associated with data theft and fraudulent activities. The group's targeting of individuals in multiple countries suggests a global operational scope, possibly aiming to maximize their reach and opportunities for gain. Their focus on impersonating local institutions may indicate an attempt to exploit trust in familiar brands or services to increase the success rate of their campaigns. The sectors targeted by TA2719—banking, law enforcement, shipping—suggest a desire to access sensitive data or disrupt specific industries. Typical victims include individuals in both private and corporate settings who receive these phishing emails, making organizations across all sectors potentially at risk.
Enhanced Description
TA2719 is a cyber threat actor that Proofpoint began tracking in late March 2020. The group primarily utilizes commodity remote access trojans (RATs) such as NanoCore and AsyncRAT to carry out its activities. TA2719's operations are characterized by localized phishing campaigns, where the actors send emails with colorful images designed to impersonate local banks, law enforcement agencies, or shipping services. These campaigns are likely intended to exploit trust in local institutions to trick recipients into opening malicious attachments or clicking on suspicious links. The group has been observed targeting individuals across a wide range of countries, including Austria, Chile, Greece, Hungary, Italy, North Macedonia, Netherlands, Spain, Sweden, Taiwan, United States, and Uruguay. Despite the use of relatively common tools like RATs, TA2719's operational approach appears to be carefully crafted to remain under the radar, with low-volume campaigns that may indicate a focus on quality over quantity. The group's targeting of multiple geographic regions suggests a potential interest in geographically diverse victimology, possibly to maximize reach or avoid detection.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA2719's campaign patterns involve low-volume, geographically diverse attacks that may be designed to evade detection. The group's focus on localized lures suggests an understanding of cultural and regional factors that could enhance the success rate of their campaigns. Despite the use of common tools like RATs, TA2719 demonstrates a level of operational maturity consistent with more advanced actors, particularly in their targeting and delivery mechanisms. Notable operations include phishing campaigns impersonating local banks and law enforcement agencies across multiple countries, indicating a broad and flexible approach to victim selection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in TA2719's profile based on available data. While the actor's use of commodity tools and identified TTPs provides a clear picture of their capabilities, specific details about their long-term goals, exact campaign history beyond what is reported by Proofpoint, and operational infrastructure remain unclear. Additional intelligence sharing and analysis would help refine understanding of this threat group.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics