Skip to main content

TA402

Repository Navigation

  • Actor workbench: TA402
  • TTP-to-detection matrix: all mapped techniques
  • Surface and capability routes: Endpoint RMM, Scripting, And User-Path Execution
  • Detection status: dashboard
  • Hunt workflow: hunt workflow
  • ATT&CK mappings: T1566.001 Spearphishing Attachment (M3); T1574.001 DLL Search Order Hijacking (M3)
  • Mapped detections: None currently mapped.
  • Mapped hunts: None currently mapped.
  • IOC reference sources: SRC-PROOFPOINT-TA402-IRONWIND Domains; payload hashes; attachment chain details; SRC-S1-ISRAEL-HAMAS-CYBER-2023 Actor context; lure and malware family references
  • Tool detail pages: IronWind
  • Tool matrix: all actor-linked tools (1 mapped tool row(s))
  • Evidence records: EVD-024 / CLM-TA402-001
  • Imported research intakes: None currently mapped.
  • Intel update candidates: 2 current candidate(s)
  • Source IDs in structured data: SRC-PROOFPOINT-TA402-IRONWIND, SRC-S1-ISRAEL-HAMAS-CYBER-2023

Background

TA402 (Molerats/Gaza Cybergang) is a Palestinian-aligned espionage group active since at least 2012, making it one of the longest-running Middle Eastern threat actors in public vendor tracking. Early campaigns (2012-2016) used commodity malware including H-Worm, njRAT, and Poison Ivy distributed through politically-themed phishing. The group gradually developed more sophisticated delivery chains and custom tooling in response to increased detection capability.

Proofpoint's November 2023 report on IronWind represents the most recent and technically significant TA402 disclosure. The report documented a shift in delivery methodology: TA402 compromised legitimate Middle East government ministry email accounts and used them as trusted senders to deliver phishing to other government entities — a trusted-sender-abuse pattern that bypasses many perimeter controls. Payloads were hosted on Dropbox using PPAM (PowerPoint add-in), XLL (Excel add-in), and RAR archive attachment chains, landing IronWind — a modular, Dropbox-communicating malware family — on target systems.

The group's targeting is diplomatic and governmental in focus: Middle East government organizations, political opposition groups, regional think tanks, and entities with insight into Palestinian Authority and regional political dynamics. For Israeli government defenders, the compromise of regional ministry accounts means that inbound messages from trusted regional government senders cannot be treated as inherently safe, and volume/attachment anomaly monitoring for established diplomatic communication channels is a practical detection requirement.

TA402 is tracked as distinct from WIRTE in this repository, though both are assessed as Hamas-affiliated and share targeting overlap. Some vendor reporting groups them under the broader "Gaza Cybergang" umbrella; analysts should note which specific cluster a source is describing before applying IOCs or TTPs from one actor profile to the other.

Aliases: Molerats, Gaza Cybergang, Extreme Jackal, Frankenstein.

Assessed sponsor: Palestinian-aligned in public reporting.

Relevance

TA402 is relevant to Israeli and regional diplomatic ecosystems because Proofpoint reported targeting of Middle East government entities with compromised ministry accounts, Dropbox-hosted lures, PPAM/XLL attachment chains, and IronWind malware.

Defensive Focus

  • Compromised trusted senders.
  • Government-themed phishing.
  • Rare Office add-ins such as PPAM and XLL.
  • Archive and file-sharing delivery chains.

Detection Ideas

  • PPAM, XLL, or RAR execution from email or download paths.
  • Dropbox or cloud-file links followed by Office add-in execution.
  • Inbound messages from partner ministries that deviate from historical volume or attachment patterns.

Sources: SRC-PROOFPOINT-TA402-IRONWIND, SRC-S1-ISRAEL-HAMAS-CYBER-2023.

Public Reports

Primary vendor reporting:

  • Proofpoint Threat Research, "IronWind: New TA402 Malware Deployed Against Middle Eastern Targets" — November 2023. Primary analysis of IronWind malware, compromised ministry sender abuse, Dropbox-hosted payload delivery, PPAM/XLL/RAR attachment chains. Source ID SRC-PROOFPOINT-TA402-IRONWIND.
  • SentinelLabs, "The Cyber Dimension of the Israel-Hamas Conflict" — 2023. Actor context for TA402 within the conflict-period Palestinian-affiliated threat landscape. Source ID SRC-S1-ISRAEL-HAMAS-CYBER-2023.
  • Cisco Talos, "Frankenstein Campaign" — Documents TA402/Molerats campaigns using commodity open-source tools with politically-themed lures targeting European governments and NGOs.
  • Kaspersky, "Operation Parliament" — 2018 coverage of Molerats/Gaza Cybergang campaigns targeting Middle East government officials and defense sector entities, including Israeli organizations.
  • Check Point Research, Gaza Cybergang reporting — Multiple reports on the broader Gaza Cybergang ecosystem of which TA402 is a component cluster; note the cluster-disambiguation requirements when applying specific IOCs.