TA459
MITRE ATT&CK: G0062 View on attack.mitre.org
Aliases: TA459
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:32:01
Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications
Targeted regions: country_code:ru country_code:by country_code:mn
Context
TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.
Detection coverage
- 12 YARA rules
- 267 Sigma rules
Malware & tools used
- Spearphishing Attachment (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Visual Basic (attack-pattern)
- Malicious File (attack-pattern)
- PowerShell (attack-pattern)
- ZeroT (malware)
- PlugX (malware)
- gh0st RAT (malware)
- NetTraveler (malware)
Reports & references
- proofpoint.com — Apt Targets Financial Analysts (report)
- MITRE ATT&CK — G0062 (report)