Also known as: G0062
TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others. (Citation: Proofpoint TA459 April 2017)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TA459 (also known as G0062) is a suspected Chinese state-sponsored threat group targeting non-governmental organizations (NGOs) in Russia, Central Asia, and surrounding regions primarily for espionage activities. The group has been linked to the deployment of sophisticated malware such as PlugX and gh0st RAT, indicating a high level of technical capability.
Goals & Targeting
TA459's strategic objectives appear to focus on gathering intelligence for potential geopolitical advantage or national security interests, likely benefitting the Chinese government. The group's targeting of NGOs in Russia and Central Asia suggests an interest in regional dynamics, sensitive diplomatic communications, and internal governance information. Its victims are typically organizations with access to information that could be valuable to state actors.
Enhanced Description
TA459 is a cyber threat actor believed to operate from China, with a primary focus on conducting espionage activities against NGOs in Russia, Central Asia, and neighboring countries. The group has been observed using malicious software such as ZeroT, PlugX, gh0st RAT, and NetTraveler, which are indicative of its advanced capabilities. TA459's operations include targeting sensitive information from government-related or quasi-governmental organizations, leveraging techniques like spear-phishing and file-based attacks. The group's activities align with broader Chinese state-sponsored cyber espionage campaigns, though its specific role and exact origin remain unclear.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA459's campaigns have targeted NGOs in Russia and Central Asia, suggesting an interest in regional political and economic developments. The group's operational tempo appears methodical, focusing on long-term access rather than immediate impact. Specific campaign details are limited, but linked intelligence indicates a preference for file-based attacks and internal network exfiltration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in TA459's linkage to China and its targeting of NGOs is based on historical data and technique correlations. Gaps include unclear origin, exact campaign details, and limited observable patterns.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
5
Techniques
6
Tools
0
Campaigns
0
IOCs
0
Observed Data
2
Tactics