Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: G0062

Description

TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others. (Citation: Proofpoint TA459 April 2017)

Goals & Targeting

Targeted Sectors

Ngo

Targeted Countries / Regions

RU
central_asia

AI Analysis

· 1 week ago

Executive Summary

TA459 (also known as G0062) is a suspected Chinese state-sponsored threat group targeting non-governmental organizations (NGOs) in Russia, Central Asia, and surrounding regions primarily for espionage activities. The group has been linked to the deployment of sophisticated malware such as PlugX and gh0st RAT, indicating a high level of technical capability.

Goals & Targeting

TA459's strategic objectives appear to focus on gathering intelligence for potential geopolitical advantage or national security interests, likely benefitting the Chinese government. The group's targeting of NGOs in Russia and Central Asia suggests an interest in regional dynamics, sensitive diplomatic communications, and internal governance information. Its victims are typically organizations with access to information that could be valuable to state actors.

Enhanced Description

TA459 is a cyber threat actor believed to operate from China, with a primary focus on conducting espionage activities against NGOs in Russia, Central Asia, and neighboring countries. The group has been observed using malicious software such as ZeroT, PlugX, gh0st RAT, and NetTraveler, which are indicative of its advanced capabilities. TA459's operations include targeting sensitive information from government-related or quasi-governmental organizations, leveraging techniques like spear-phishing and file-based attacks. The group's activities align with broader Chinese state-sponsored cyber espionage campaigns, though its specific role and exact origin remain unclear.

Key Capabilities

  • Sophisticated malware development (e.g., PlugX, gh0st RAT)
  • Spear-phishing campaigns
  • Use of remote administrative tools
  • Exploitation of client execution vulnerabilities
  • Malicious file deployment

MITRE ATT&CK Tactics

Espionage
Initial Access

ATT&CK Techniques

T1204.002
T1059.001
T1203
T1566.001
T1059.005

Software / Tooling

ZeroT
PlugX
gh0st RAT
NetTraveler

Campaigns & Victims

TA459's campaigns have targeted NGOs in Russia and Central Asia, suggesting an interest in regional political and economic developments. The group's operational tempo appears methodical, focusing on long-term access rather than immediate impact. Specific campaign details are limited, but linked intelligence indicates a preference for file-based attacks and internal network exfiltration.

IOC Patterns

  • Spear-phishing emails with malicious附件 (e.g., .exe or .doc files)
  • Use of VBScript payloads
  • Remote administrative tool deployments
  • C2 communication via standard protocols

Recommended Actions

  • Implement training on spear-phishing and file-based threats
  • Monitor for T1059 (PowerShell) and T1059.005 (VBScript) activities
  • Enhance endpoint detection to identify known malicious tools like PlugX
  • Conduct regular network traffic analysis focused on C2 indicators

Suggested Tags

APT
espionage
non-governmentalorganizations
RU
central_asia
malware

Confidence Assessment

Moderate confidence in TA459's linkage to China and its targeting of NGOs is based on historical data and technique correlations. Gaps include unclear origin, exact campaign details, and limited observable patterns.

Intel Summary

5

Techniques

6

Tools

0

Campaigns

0

IOCs

0

Observed Data

2

Tactics

Tags

APT
espionage
non-governmentalorganizations
RU
central_asia
malware

Details

MITRE ID
G0062
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--62a64fd3-aaf7-4d09-a375-d6f8bb118481
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.