Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

TA402 is an APT group that has been tracked by Proofpoint since 2020. They primarily target government entities in the Middle East and North Africa, with a focus on intelligence collection. TA402 is known for using sophisticated phishing campaigns and constantly updating their malware implants and delivery methods to evade detection. They have been observed using cloud services like Dropbox and Google Drive for hosting malicious payloads and command-and-control infrastructure.

AI Analysis

· 1 week ago

Executive Summary

TA402 is an Advanced Persistent Threat (APT) group targeting Middle Eastern and North African governments since 2020, focusing on intelligence collection through sophisticated phishing campaigns and malware.

Goals & Targeting

TA402's strategic objectives involve long-term access to target networks to gather sensitive intelligence. Their focus on Middle Eastern governments suggests a potential interest in geopolitical information or influence.

Enhanced Description

TA402 operates as a state-sponsored APT group primarily active in the Middle East and North Africa, with a focus on government entities. They employ advanced phishing techniques using custom malware and regularly update their tools to avoid detection. TA402 leverages cloud services like Dropbox and Google Drive for malicious activities, including payload delivery and command-and-control infrastructure.

Key Capabilities

  • Sophisticated phishing campaigns
  • Custom malware development
  • Cloud service abuse for C2 infrastructure

MITRE ATT&CK Tactics

Adversary-in-the-Cloud

ATT&CK Techniques

T1059
T1566

Software / Tooling

Custom Malware
Cloud Service Abuse Tools

Campaigns & Victims

TA402 has consistently targeted government entities since 2020, utilizing persistent and evasive techniques. Their campaigns often involve long-term access to facilitate data exfiltration.

IOC Patterns

  • Spear-phishing emails
  • Malicious links in cloud storage
  • Command-and-control via legitimate services

Recommended Actions

  • Implement advanced email filtering solutions
  • Monitor cloud service logs for suspicious activity
  • Conduct regular user training on phishing awareness

Suggested Tags

APT
Government Targeting
Intelligence Collection
Middle East

Confidence Assessment

High confidence in TA402's APT nature and targeting patterns. Limited data on specific tools or campaigns beyond initial reports.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Phishing
Backdoor / C2
Government Targeting
Intelligence Collection
Middle East

Details

Type
Unknown
Country of Origin
P
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.