TA2725 is a threat actor tracked by Proofpoint since March 2022. It is known for using Brazilian banking malware and credential phishing to target organizations mainly in Brazil, Mexico, and Spain. Proofpoint attributes to TA2725 use of Brazilian banking malware including Mispadu, Astaroth, and historically Grandoreiro. TA2725 has conducted campaigns targeting bank credentials in Brazil and Mexico, and has also targeted consumer credentials and payment information for Netflix and Amazon accounts. In late August 2023, Proofpoint observed two TA2725 campaigns, running from 24 through 29 August 2023, that shared common infrastructure and payloads while targeting both Mexico and Spain simultaneously. Those campaigns used an updated Grandoreiro build with credential-stealing banking overlays for both Spain and Mexico in the same malware build. Proofpoint also observed a TA2725 campaign targeting Spain in August and September that spoofed ÉSECÈ Group, a Spanish manufacturing company. TA2725 typically delivers malware via phishing and URL-based delivery. Proofpoint reported that it commonly hosts URL redirectors on GoDaddy virtual hosting and redirects victims to ZIP files hosted on legitimate cloud providers such as Amazon AWS, Google Cloud, or Microsoft Azure. Grandoreiro delivery observed in TA2725-attributed activity used phishing emails containing URLs that led to ZIP archives with loaders such as MSI, HTA, or EXE files; the loader then used DLL injection and downloaded the final payload. In January 2025, TA2725 began delivering ScreenConnect for the first time. Proofpoint observed these campaigns using energy bill lures and compressed executables targeting organizations in Mexico. Proofpoint also noted that TA2725 had used a 'photo of physical mail' social-engineering technique in recent months. Known alias in the provided content: ta2725.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another actor observed using a rare social-engineering lure technique (customized photo of purported physical mail showing recipient name/address). No additional operational details provided in this content.
Cybercriminal threat actor known for Brazilian banking malware and credential phishing; expanded to delivering ScreenConnect as a first-stage payload in campaigns targeting Mexico.
Uses Brazilian banking malware and phishing to target organizations and users, primarily in Brazil and Mexico, and more recently Spain. The group delivers Grandoreiro to steal banking credentials, consumer credentials, and payment information, including for Netflix and Amazon accounts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.