TA402TA402

Also known as: TA402

Known aliases
1

Profile

TA402 is an APT group that has been tracked by Proofpoint since 2020. They primarily target government entities in the Middle East and North Africa, with a focus on intelligence collection. TA402 is known for using sophisticated phishing campaigns and constantly updating their malware implants and delivery methods to evade detection. They have been observed using cloud services like Dropbox and Google Drive for hosting malicious payloads and command-and-control infrastructure.

Aliases· 1

TA402

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
TA482
Actor
TA406
Actor
APT42
Actor
TAG-140
Actor
TA455
Actor
APT.3102
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.