TA2536
- First seen
- 2015-01-01 00:00:00
- Origin
- NG
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- individual
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:03:51
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
TA2536, which has been active since at least 2015, is likely Nigerian based on its unique linguistic style, tactics and tools. It uses keyloggers such as HawkEye and distinctive stylometric features in typo-squatted domains that resemble legitimate names and the use of recurring names and substrings in email addresses.
Detection coverage
- 11 YARA rules
Malware & tools used
- Nanocore RAT (malware)
- Agent Tesla (malware)
- Remcos (malware)
- LokiBot (malware)
- Formbook (malware)
- HawkEye Keylogger (malware)
Reports & references
- proofpoint.com — Dtpacker Net Packer Curious Password 1 (report)