TA866

First seen
2019-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
Financial Theft
Profile updated
2026-07-07 12:04:16

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector

Context

According to Proofpoint, TA866 is a newly identified threat actor that distributes malware via email utilizing both commodity and custom tools. While most of the activity observed occurred since October 2022, Proofpoint researchers identified multiple activity clusters since 2019 that overlap with TA866 activity. Most of the activity recently observed by Proofpoint suggests recent campaigns are financially motivated, however assessment of historic related activities suggests a possible, additional espionage objective.

Detection coverage

  • 4 YARA rules

Malware & tools used

Reports & references

  • proofpoint.com — Screentime Sometimes It Feels Like Somebodys Watching Me (report)

External references