TA459

MITRE ATT&CK: G0062 View on attack.mitre.org

Aliases: TA459

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:32:01

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications

Targeted regions: country_code:ru country_code:by country_code:mn

Context

TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.

Detection coverage

  • 12 YARA rules
  • 267 Sigma rules

Malware & tools used

  • Spearphishing Attachment (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Visual Basic (attack-pattern)
  • Malicious File (attack-pattern)
  • PowerShell (attack-pattern)
  • ZeroT (malware)
  • PlugX (malware)
  • gh0st RAT (malware)
  • NetTraveler (malware)

Reports & references

  • proofpoint.com — Apt Targets Financial Analysts (report)
  • MITRE ATT&CK — G0062 (report)

External references