TA406 Launches Credential-Theft Campaign Against Government Entities

TA406 Launches Credential-Theft Campaign Against Government Entities

North Korea-Backed TA406 Escalates Targeted Cyber Operations Against Ukraine

Since February 2025, the North Korea-aligned threat group TA406 has ramped up its targeted cyber intrusions against Ukrainian governmental institutions, utilizing advanced phishing tactics to compromise credentials and deploy surveillance-oriented malware.

Linked to activity clusters such as Opal Sleet and Konni, TA406 appears to have strategically pivoted its objectives—zeroing in on gathering high-value intelligence related to Ukraine’s evolving political and military stance during the continued Russian incursion.

Cybersecurity experts at Proofpoint have observed TA406 masquerading as academics from think tanks, distributing carefully crafted phishing emails from hijacked email accounts. These messages often include links or attachments that mimic legitimate geopolitical analyses, aligning with Pyongyang’s long-standing pattern of leveraging global instability to bolster its intelligence arsenal.

In recent campaigns, the group fabricated entities such as the “Royal Institute of Strategic Studies,” allegedly reaching out through individuals like the fictional Dr. John Smith. Recipients are lured into opening password-protected RAR files hosted on legitimate cloud platforms like MEGA.

Once extracted, these archives reveal a CHM file cloaked as a policy briefing. Upon interaction, this file activates embedded PowerShell scripts engineered to silently extract system information—ranging from active processes and network settings to endpoint protection data.

TA406’s modular malware architecture allows for multi-stage payload execution, with stolen data exfiltrated to attacker-controlled infrastructure. Analysts report that this information is often used to tailor subsequent attack phases more precisely.

The group employs persistence techniques that embed scheduled tasks and batch scripts deep within the user profile, such as the creation of a state.bat file configured to run at system startup, securing a foothold for long-term access.

A standout example from February 2025 includes a phishing lure titled “Meet Valerii Zaluzhnyi, Ukraine’s former army chief who could challenge Volodymyr Zelenskyy in the presidential election.” The campaign exemplified TA406’s blending of topical bait and technical precision to maximize infiltration success.

Deceptive Payload Delivery via Weaponized CHM and LNK Files

In a recent campaign uncovered by Proofpoint, TA406 leveraged stealthy PowerShell-based delivery mechanisms embedded within deceptive file formats to exfiltrate sensitive system data from targeted Ukrainian government machines.

At the center of one attack chain was a booby-trapped CHM file, misleadingly titled Analytical Report.chm. This file, although disguised as a legitimate help document, was wired with HTML pages containing hidden PowerShell instructions. When opened, the CHM file automatically triggered a command initiating a connection to the actor-controlled URL:
hxxp://pokijhgcfsdfghnj.mywebcommunity[.]org/main/test.txt.

This endpoint delivered an additional layer of obfuscated PowerShell code, designed to harvest contextual host data such as environment variables, file metadata, and usage patterns. Key data points were serialized in Base64 format and transmitted to the command-and-control server via HTTP POST, using a structure resembling:

Collect and transmit recent activity

While this payload focused on reconnaissance, a separate campaign deployed parallel tactics with slightly altered techniques. In this variant, TA406 distributed phishing emails bearing HTML attachments that, when opened, redirected victims to download a ZIP archive from:
hxxps://lorica[.]com.ua.

Inside the archive, users encountered a deceptively named LNK shortcut—Why Zelenskyy fired Zaluzhnyi.lnk. On execution, the shortcut decoded and ran embedded PowerShell code which, in turn, dropped a JavaScript Encoded (JSE) script onto the system. This secondary file was responsible for creating persistence mechanisms, ensuring the malware would relaunch after reboot.

The convergence of misleading file formats (CHM, LNK), legitimate-looking URLs, and layered obfuscation techniques underlines TA406’s evolving sophistication in blending social engineering with technical precision. These campaigns not only reflect an agile malware delivery model but also highlight the group’s intent to remain embedded in target environments for extended surveillance.

Screenshot

TA406 Leverages Encoded PowerShell and Task Scheduler for Persistent Access

In a recent wave of cyber activity, TA406 deployed malicious LNK files embedded with Base64-encoded PowerShell commands designed to execute stealthily upon user interaction. One observed command decoded and executed PowerShell expressions that quietly initialized secondary payloads:

This script acted as a launchpad for a JavaScript Encoded (JSE) file, which played a critical role in establishing persistence on infected machines. The JSE created a scheduled task camouflaged as a legitimate system process—“Windows Themes Update”—configured to beacon out to TA406’s infrastructure once every minute. The command-and-control (C2) endpoint in this case was:
hxxp://wersdfxcv.mygamesonline[.]org.

Confirmed Indicators of Compromise (IOCs)

  • Command-and-Control Infrastructure:
    • pokijhgcfsdfghnj.mywebcommunity[.]org
    • wersdfxcv.mygamesonline[.]org
  • Malicious File Hashes:
    • 58adb6b87a3873f20d56a10ccde457469adb5203f3108786c3631e0da555b917 (associated RAR archive)
  • Spoofed Sender Email Addresses:
    • john.dargavel.smith46@gmail[.]com
    • Microft Acount Tearns@protonmail[.]com (intentionally misspelled for evasion)

These artifacts point to a well-resourced adversary with clear objectives: sustain covert access, harvest intelligence, and track developments within Ukraine’s political and defense structures. Proofpoint researchers emphasize that such efforts are in line with North Korea’s broader geopolitical interests, particularly in capitalizing on regional instability.

Defensive Recommendations

Security teams are urged to apply heightened scrutiny to unsolicited messages referencing military or political developments, especially those prompting downloads from unknown sources. Blocking known malicious domains and email addresses, while inspecting PowerShell activity within endpoints, remains critical to mitigating ongoing threats from TA406.

More Articles & Posts