Uptime Hamster: 10d 12h 49mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza TA2723

TA2723

0 incidentes 0 paises 0 sectores apt Global Ultimo: -
Ver en IntelTracker → APTTrail →
TA2723 is a financially motivated cybercriminal group that has been active since at least 2022, initially known for participating in credential phishing campaigns and distributing malware via fake browser update lures. The group has been observed collaborating with other operators such as TA569 (SocGholish) and TA2726 to distribute infostealers like RedLine Stealer. Beginning in October 2025, TA2723 significantly evolved its tactics, pivoting to high-volume OAuth device code phishing campaigns primarily targeting Microsoft 365 accounts, leveraging legitimate Microsoft authorization flows to bypass traditional security measures and multi-factor authentication.
Tecnicas MITRE
T1102.002 - Bidirectional Communication, T1552 - Unsecured Credentials, T1534 - Internal Spearphishing, T1204.002 - Malicious File, T1550.001 - Application Access Token, T1566.002 - Spearphishing Link
Tipo
apt
Pais origen
Global
Motivacion
-
Impacto
11
Actualizado
Mon, 05 Ma

Sectores objetivo (SOCRadar)

Energy & Utilities Wholesale TradeTransportation&WarehousingInformation ServicesFinanceEducational ServicesPublic AdministrationOther Information ServicesInsuranceJustice & Safety Activities