TA402 is an APT group targeting Middle Eastern and North African governments using cloud services for C2 and delivery.
Analyst brief
TA402 is an APT group tracked since 2020, primarily targeting government entities in the Middle East and North Africa for intelligence collection. They employ sophisticated phishing campaigns, continuously updated malware implants, and delivery methods to evade detection. The group leverages cloud services like Dropbox and Google Drive for hosting malicious payloads and its C2 infrastructure. Defenders should focus on email security, especially phishing attacks aimed at government users, and monitor for anomalous traffic to cloud services.
TA402
unknown
TA402 is an APT group that has been tracked by Proofpoint since 2020. They primarily target government entities in the Middle East and North Africa, with a focus on intelligence collection. TA402 is known for using sophisticated phishing campaigns and constantly updating their malware implants and delivery methods to evade detection. They have been observed using cloud services like Dropbox and Google Drive for hosting malicious payloads and command-and-control infrastructure.