TA2536 is a Nigerian cybercriminal group active since at least 2015, known for credential phishing and HawkEye keylogger usage.
Analyst brief
TA2536 is likely a Nigerian cybercriminal group active since at least 2015. It primarily targets individuals and organizations through phishing campaigns using typo-squatted domains to steal credentials. The group employs keyloggers like HawkEye and exhibits distinctive stylometric patterns, including recurring names in email addresses. Defenders should heighten awareness of phishing emails exploiting domain similarity and enhance endpoint monitoring for suspicious processes.
TA2536
unknown
TA2536, which has been active since at least 2015, is likely Nigerian based on its unique linguistic style, tactics and tools. It uses keyloggers such as HawkEye and distinctive stylometric features in typo-squatted domains that resemble legitimate names and the use of recurring names and substrings in email addresses.