TA2536, which has been active since at least 2015, is likely Nigerian based on its unique linguistic style, tactics and tools. It uses keyloggers such as HawkEye and distinctive stylometric features in typo-squatted domains that resemble legitimate names and the use of recurring names and substrings in email addresses.
Executive Summary
TA2536 is a cyber threat actor likely based in Nigeria, identified by unique linguistic patterns, tactics, and tools. Active since 2015, TA2536 targets financial and retail sectors globally, using keyloggers like HawkEye and distinctive typo-squatting domains to compromise victims.
Goals & Targeting
TA2536's objectives appear to be primarily financial, aiming to extract sensitive information and funds from targeted industries. The group’s choice of victims aligns with sectors where data breach or financial theft can yield significant monetary returns. By leveraging their unique linguistic and technical methods, TA2536 focuses on global organizations across multiple geographies, reflecting a patient and methodical approach to achieving long-term financial gain.
Enhanced Description
TA2536, first observed in activity as early as 2015, is believed to be based in Nigeria due to its linguistic style and operational methods. This group primarily focuses on financial gain through sophisticated cyberattacks targeting sectors with high monetary value such as banking, e-commerce, and financial services. TA2536 employs keyloggers, including the known HawkEye malware, and utilizes stylometric features in typo-squatting domains to mimic legitimate organizations. Their attack patterns, which include spear-phishing campaigns and email address substring reuse, indicate a focus on persistent, financially motivated cyber operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA2536 has demonstrated sustained activity over several years, focusing on prolonged campaigns that target financially lucrative sectors. Their use of persistent techniques and custom tools suggests an evolved operational framework. Campaign patterns include patient hunting for high-value targets within the financial sector, with a particular emphasis on compromising sensitive customer data.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Relatively high confidence level in TA2536 being a financially motivated group targeting the financial and retail sectors. However, gaps exist regarding exact campaign details beyond 2015 and specific TTP evolution.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics