TA499 logo

TA499

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: Lexus, Vovan
Ver en IntelTracker → APTTrail →
TA499, also known by the aliases Vovan and Lexus, is a Russia-aligned threat actor that emerged with email campaigns in early 2021, intensifying its efforts after Russia's invasion of Ukraine in February 2022. The group's primary motivation is a pro-Russia propaganda effort, specifically designed to generate negative political content about individuals who criticize Russian President Vladimir Putin or oppose Russia's actions in Ukraine. What distinguishes TA499 is its method of operation, which involves aggressively using email campaigns to solicit video call requests from high-profile individuals, then impersonating officials, potentially with the use of deepfake technology, to create and disseminate politically damaging content.
Tecnicas MITRE
T1003.003, T1498 - Network Denial of Service, T1218 - Signed Binary Proxy Execution, T1078.001, T1140 - Deobfuscate/Decode Files or Information, T1105

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
6
Actualizado
Wed, 08 No

Sectores objetivo (SOCRadar)

Enterprises & HoldingPublic Administration