TA2722 is a financially motivated cybercriminal threat actor known for phishing-led malware delivery and credential-harvesting operations that impersonate Philippine government and related entities. The actor has been associated with lures themed around the Philippine Department of Health, the Philippine Overseas Employment Administration, the Bureau of Customs Client Profile Registration System, the Saudi embassy in Manila, and DHL Philippines. Proofpoint has also referred to the actor internally as the Balikbayan Foxes. Activity attributed to TA2722 has been divided into two closely related clusters, Shahzad73 and CPRS, which are assessed to belong to the same actor based on overlapping victims and infrastructure patterns. TA2722 has targeted organizations across North America, Europe, and Southeast Asia, with repeated victimization in shipping, logistics, manufacturing, business services, pharmaceuticals, energy, and finance. The targeting pattern indicates a focus on organizations that directly or indirectly interact with Philippine government processes, especially customs, labor, and health-related workflows. The actor commonly gains initial access through phishing emails carrying malicious attachments or links. Observed delivery mechanisms include cloud-hosted archives, compressed attachments containing embedded payloads, disk image files, PDF lures linking to malware, and macro-enabled Microsoft Excel documents. TA2722 has used the Remcos and NanoCore remote access trojans to establish remote control over victim systems. These tools support monitoring, information gathering, data theft, and follow-on payload delivery. In later activity, the actor also shifted some campaigns toward credential harvesting against many of the same organizations previously targeted with malware. TA2722 demonstrates sustained operational activity dating back at least to 2018 for the CPRS cluster and to 2020 for Shahzad73, indicating a durable campaign set rather than a short-lived intrusion cluster. Historic reporting also links TA2722 to use of NanoCore, a commodity remote access trojan frequently employed for keylogging, remote command execution, file theft, persistence, and process injection. Overall, TA2722 is best characterized as a persistent cybercriminal actor specializing in socially engineered initial access, remote-access malware deployment, credential theft, and follow-on collection against globally distributed commercial targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historically observed using NanoCore RAT in campaigns referenced by the content.
Highly active cybercriminal threat actor conducting phishing and malware delivery campaigns themed around Philippine government and related entities, targeting organizations in North America, Europe, and Southeast Asia to gain remote access, steal information, and potentially enable follow-on malware or BEC activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.