TA410
Medium ConfidenceMedium ThreatLookingFrog • FlowingFrog • JollyFrog
TA410 is a Chinese-linked cyber espionage group that has been active since at least 2018, primarily targeting U.S. utilities and government organizations. The group is known for using the FlowCloud and LookBack malware families. TA410 demonstrates sophisticated capabilities including custom tool development and careful operational security. Their targeting of critical infrastructure, particularly the energy sector, suggests alignment with Chinese strategic intelligence priorities.
TA410 is a Chinese-linked cyber espionage group that has been active since at least 2018, primarily targeting U.S. utilities and government organizations. The group is known for using the FlowCloud and LookBack malware families. TA410 demonstrates sophisticated capabilities including custom tool development and careful operational security. Their targeting of critical infrastructure, particularly the energy sector, suggests alignment with Chinese strategic intelligence priorities.
Target Sectors
Target Regions
Attributed to MSS (Ministry of State Security) (China). Attribution confidence: Medium.
Future Outlook
TA410 is expected to continue operations targeting Utilities sectors.
First observed activity of TA410
Continued active operations