TA406
TA406 is engaging in malware distribution, phishing, intelligence collection, and cryptocurrency theft, resulting in a wide range of criminal activities.
TA406 is a cybercriminal group known for cryptocurrency theft and targeted spear-phishing against governments and NGOs.
TA406 is a threat actor engaged in diverse criminal activities, including malware distribution, phishing, intelligence collection, and cryptocurrency theft. This group targets government entities, journalists, and NGOs across China, France, Germany, India, Japan, North America, Russia, South Africa, South Korea, and the United Kingdom. Their key TTPs involve tailored spear-phishing campaigns, custom malware loaders, and tools designed to drain cryptocurrency wallets. Defenders should reinforce email security protocols, conduct user awareness training against targeted phishing, and monitor network anomalies related to unauthorized cryptocurrency transactions.
TA406 is engaging in malware distribution, phishing, intelligence collection, and cryptocurrency theft, resulting in a wide range of criminal activities.
Their key TTPs involve tailored spear-phishing campaigns, custom malware loaders, and tools designed to drain cryptocurrency wallets.
This group targets government entities, journalists, and non-governmental organizations (NGOs).
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.