◇ SIGN IN
← all actors
apt

TA402 / Molerats (2021–2023 activity)

activehigh confidence
APT / State-sponsored
MoleratsGaza CybergangFrankensteinRenegade Jackal
Attribution
Palestinian — assessed aligned with Palestinian Territory interests
Origin
Palestinian Territories
First seen
2012
Last active
2024
Motivation
Espionage
Confidence
high
MENA targeting
Middle East governments (Palestine-focused interests)
Sectors
Government, banking, political parties, journalists/activists
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Middle East governments (Palestine-focused interests) (Government, banking, political parties sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

TA402 is Proofpoint's designation for a Molerats/Gaza Cybergang-aligned Palestinian APT that runs highly selective, well-crafted phishing operations against Middle Eastern and North African government entities, most recently delivering the IronWind downloader.

History

TA402 is the name Proofpoint uses for a Middle Eastern APT that historically operates in the interests of the Palestinian Territories and overlaps with the Molerats / Gaza Cybergang cluster (MITRE folds this activity into Molerats, G0021). It is characterized by disciplined, narrowly scoped targeting rather than broad campaigns.

The group's tradecraft emphasizes convincing geopolitical lures, frequent malware and delivery refreshes, and abuse of legitimate services. Between July and October 2023 Proofpoint observed TA402 delivering a new multi-stage initial-access downloader dubbed IronWind, repeatedly changing delivery methods — from Dropbox links to XLL and RAR attachments and PowerPoint add-ins (PPAM) — to evade detection, in one case abusing a compromised Ministry of Foreign Affairs email account.

MENA government entities are TA402's defining target set. The group pursues government organizations across the Middle East and North Africa, typically fewer than five organizations per campaign, reflecting an intelligence-collection mission tightly focused on regional political and diplomatic developments.

TA402 is assessed as continuing to operate through the ongoing regional conflict, adapting lure content to current events. Its relationship to the broader Molerats umbrella and the WIRTE sub-cluster means TA402 activity should be read alongside the wider Palestinian-aligned espionage ecosystem, which has both persisted in espionage and, via related clusters, expanded into disruptive operations.

Notable campaigns

2021
NimbleMamba / geopolitical lures
Proofpoint-documented espionage against Middle Eastern governments and journalists using the NimbleMamba implant.
2023
IronWind infection chains
Multi-stage IronWind downloader delivered to MENA government targets with evolving XLL/RAR/PPAM delivery methods.