TA2726
TA2726 is a financially motivated threat actor cluster assessed to function primarily as a traffic provider or traffic distribution service for other threat actors. Reporting links TA2726 to operation of Parrot TDS and abuse of Keitaro TDS/Keitaro Tracker, including use of stolen or cracked Keitaro licenses. TA2726 has been described as compromising websites and injecting Keitaro TDS links, then selling or brokering that traffic to customers including other malware actors. The cluster is specifically linked to supporting SocGholish/FakeUpdates and TA2727. Multiple reports state that TA2726 functioned as a traffic provider for SocGholish and TA2727 by compromising websites and injecting Keitaro TDS links for resale. Proofpoint assessed that TA2726 may act as a traffic distribution service for other threat actors, and that TA2726 and TA2727 were both involved in web-inject campaigns using fake browser update lures. TA2726 and TA2727 have both been linked to fake browser updates as an attack vector, and FrigidStealer activity has been linked to both clusters. Observed tactics and tradecraft directly mentioned in the reporting include use of traffic distribution systems, website compromise, malicious web injects, fake browser update lures, and traffic brokering/resale. TA2726 is also described as operating infrastructure used to route victims to downstream malicious activity. Content does not directly attribute malware development to TA2726; rather, the high-confidence characterization is that it provides and monetizes traffic and redirection infrastructure used by other actors. Known alias in the provided content: TA2726.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with abuse of Keitaro TDS using stolen or cracked licenses for malicious activity.
Identified as a major malware actor using illicit copies of the Keitaro tracker as part of its operations.
Acts as a traffic provider by compromising websites, injecting Keitaro TDS links, and selling that traffic/redirection capability to customers supporting SocGholish and TA2727 activity.
Traffic provider/redirector cluster that compromises webpages and injects Keitaro TDS links, then resells/redirects that traffic to SocGholish and other actors (e.g., TA2727; historically also VexTrio per the report’s assessment).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.