TA2723
0 incidentes
0 paises
0 sectores
apt Global Ultimo: -
TA2723 is a financially motivated cybercriminal group that has been active since at least 2022, initially known for participating in credential phishing campaigns and distributing malware via fake browser update lures. The group has been observed collaborating with other operators such as TA569 (SocGholish) and TA2726 to distribute infostealers like RedLine Stealer. Beginning in October 2025, TA2723 significantly evolved its tactics, pivoting to high-volume OAuth device code phishing campaigns primarily targeting Microsoft 365 accounts, leveraging legitimate Microsoft authorization flows to bypass traditional security measures and multi-factor authentication.
Sectores objetivo (SOCRadar)
Energy & Utilities Wholesale TradeTransportation&WarehousingInformation ServicesFinanceEducational ServicesPublic AdministrationOther Information ServicesInsuranceJustice & Safety Activities