TA2726 is a financially motivated threat actor that emerged in September 2022 as an operator of a Traffic Distribution System. This group acts as an intermediary service provider for other financially motivated threat actors, such as TA569 and TA2727, by compromising legitimate websites and injecting malicious code. They then redirect visitors to various malware payloads based on victim profiling, effectively reselling access to compromised web traffic. TA2726 specializes in creating the initial attack vector for subsequent malware distribution campaigns, rather than directly distributing malware via email or conducting the final stages of a compromise. They are distinct in their role as a backbone infrastructure provider within the cybercrime ecosystem, enabling a wide range of malware delivery without direct engagement in the payload deployment or post-exploitation activities.
Tipo
apt
Pais origen
Global
Motivacion
-
Impacto
27
Actualizado
Mon, 05 Ma
Paises objetivo (SOCRadar)
CanadaGermanySpainFranceUnited KingdomUkraineUnited States
Sectores objetivo (SOCRadar)
ConstructionRetailEducational ServicesAccommodation&Food ServicesOtherPublic AdministrationConstruction of BuildingsFood ManufacturingOther Information ServicesAccommodation