TA402

First seen
2020-01-01 00:00:00
Origin
PS
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:10:06

Targeted industries: government-and-public-sector

Targeted regions: country_code:il country_code:sa country_code:eg country_code:jo country_code:ae country_code:ma

Context

TA402 is an APT group that has been tracked by Proofpoint since 2020. They primarily target government entities in the Middle East and North Africa, with a focus on intelligence collection. TA402 is known for using sophisticated phishing campaigns and constantly updating their malware implants and delivery methods to evade detection. They have been observed using cloud services like Dropbox and Google Drive for hosting malicious payloads and command-and-control infrastructure.

Reports & references

  • proofpoint.com — Ta402 Uses Complex Ironwind Infection Chains Target Middle East Based Government (report)
  • proofpoint.com — Ugg Boots 4 Sale Tale Palestinian Aligned Espionage (report)

External references