TA4903 is a financially motivated cybercriminal threat actor focused on large-scale credential phishing and follow-on business email compromise. Activity associated with the cluster has been observed since at least 2021, with related phishing and BEC tradecraft traceable as far back as 2019. The actor primarily targets organizations in the United States, while also conducting broader global campaigns. TA4903 is known for impersonating U.S. government entities and later expanding to private-sector brands and small and medium-sized businesses. Reported impersonation themes have included multiple U.S. federal departments and commercial organizations across construction, manufacturing, energy, finance, healthcare, and food and beverage. Campaigns commonly use phishing emails containing direct links, HTML attachments, ZIP archives containing HTML, or multi-page PDF lures with embedded links and QR codes. The actor has used Microsoft 365-themed credential harvesting pages and government-branded phishing portals to steal usernames, passwords, and access to enterprise accounts. The group has also conducted business email compromise operations using supplier-spoofing and payment-related social engineering. Observed BEC themes include cyberattack notifications, invoicing, remittance, banking-change requests, payroll redirection, and thread hijacking preparation. Evidence from controlled credential seeding indicates that stolen mailbox access was used to search for payment-related terms, supporting assessment that credential theft serves as a precursor to financial fraud. During 2023, TA4903 used adversary-in-the-middle tooling associated with EvilProxy to bypass multifactor authentication in some campaigns. By 2026, the actor had shifted heavily toward device code phishing, abusing the OAuth 2.0 device authorization grant flow to obtain Microsoft 365 access tokens through legitimate sign-in infrastructure. In these campaigns, TA4903 impersonated organizations such as Microsoft and DocuSign, often delivering PDF lures with QR codes and CAPTCHA-style social engineering. The actor’s device code phishing kits were assessed to resemble EvilTokens-style tooling, and this technique appears to have largely replaced earlier BEC-linked phishing workflows in observed operations. TA4903 operates at high campaign volume, routinely registers spoofed domains, and alternates between credential theft and financially driven email fraud. Its tradecraft emphasizes spoofing, credential theft, session and token abuse, and post-compromise use of victim mailboxes to enable fraud and further social engineering.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated actor using device code phishing while impersonating Microsoft and DocuSign with custom phishing kits.
Financially motivated actor using device code phishing with Microsoft and DocuSign impersonation.
Conducting device code phishing campaigns to gain unauthorized access to Microsoft 365 accounts, using PDF attachments and CAPTCHA-themed social engineering while impersonating services such as Microsoft, DocuSign, and Norton.
Cybercriminal actor using device code phishing almost exclusively to steal credentials and compromise Microsoft 365 accounts, often impersonating businesses, government entities, or HR contacts via PDF/QR-code lures.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.