TA459
TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.
TA459 is a China-based threat group known for targeting Russia, Belarus, and Mongolia with spearphishing and RATs.
TA459 is a threat group believed to operate from China, targeting countries such as Russia, Belarus, and Mongolia. Their primary initial access vector is spearphishing attachments, followed by execution using Visual Basic and exploitation for client execution to deploy malware like gh0st RAT, NetTraveler, PlugX, and ZeroT. Defenders should implement strict attachment filtering, block suspicious macro execution, and monitor for indicators associated with these remote access trojans (RATs) and their C2 infrastructure.
TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.
Monitor emails with suspicious attachments and educate users not to open unexpected attachments.
Monitor Visual Basic script execution and signs of exploitation in client applications, and restrict VB script execution and keep client applications up-to-date.
TA459 targets countries including Russia, Belarus, and Mongolia.
TA459 uses spearphishing attachments as their primary initial access vector.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.