Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TA2536

Description

TA2536, which has been active since at least 2015, is likely Nigerian based on its unique linguistic style, tactics and tools. It uses keyloggers such as HawkEye and distinctive stylometric features in typo-squatted domains that resemble legitimate names and the use of recurring names and substrings in email addresses.

AI Analysis

· 1 week ago

Executive Summary

TA2536 is a cyber threat actor likely based in Nigeria, identified by unique linguistic patterns, tactics, and tools. Active since 2015, TA2536 targets financial and retail sectors globally, using keyloggers like HawkEye and distinctive typo-squatting domains to compromise victims.

Goals & Targeting

TA2536's objectives appear to be primarily financial, aiming to extract sensitive information and funds from targeted industries. The group’s choice of victims aligns with sectors where data breach or financial theft can yield significant monetary returns. By leveraging their unique linguistic and technical methods, TA2536 focuses on global organizations across multiple geographies, reflecting a patient and methodical approach to achieving long-term financial gain.

Enhanced Description

TA2536, first observed in activity as early as 2015, is believed to be based in Nigeria due to its linguistic style and operational methods. This group primarily focuses on financial gain through sophisticated cyberattacks targeting sectors with high monetary value such as banking, e-commerce, and financial services. TA2536 employs keyloggers, including the known HawkEye malware, and utilizes stylometric features in typo-squatting domains to mimic legitimate organizations. Their attack patterns, which include spear-phishing campaigns and email address substring reuse, indicate a focus on persistent, financially motivated cyber operations.

Key Capabilities

  • Keylogger deployment (e.g., HawkEye)
  • Typo-squatting domain registration
  • Stylometric analysis for phishing campaigns
  • Spear-phishing with email substring reuse

MITRE ATT&CK Tactics

Credential Access
Exfiltration
Persistance

ATT&CK Techniques

T1056
T1025
T1568.003

Software / Tooling

HawkEye
Custom keylogging malware

Campaigns & Victims

TA2536 has demonstrated sustained activity over several years, focusing on prolonged campaigns that target financially lucrative sectors. Their use of persistent techniques and custom tools suggests an evolved operational framework. Campaign patterns include patient hunting for high-value targets within the financial sector, with a particular emphasis on compromising sensitive customer data.

IOC Patterns

  • Spear-phishing emails with domain typosquatting
  • Recurring email substring reuse
  • Keylogger activity linked to HawkEye malware

Recommended Actions

  • Implement multi-factor authentication (MFA) for critical systems and financial transactions
  • Educate employees about phishing tactics and stylometric anomalies in emails
  • Monitor network traffic for Indicators of Compromise related to TA2536's TTPs

Suggested Tags

APT
fraudulent activity
financial sector

Confidence Assessment

Relatively high confidence level in TA2536 being a financially motivated group targeting the financial and retail sectors. However, gaps exist regarding exact campaign details beyond 2015 and specific TTP evolution.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
APT
fraudulent activity
financial sector

Details

Type
Unknown
Country of Origin
N
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.