TA2730 is a financially motivated credential-phishing threat actor tracked since June 2025. The group specializes in harvesting credentials associated with financial institutions, particularly investment-focused organizations, with the apparent objective of taking over investment accounts for monetary gain. Its activity has been characterized as largely opportunistic rather than highly targeted. TA2730 is known for phishing campaigns that impersonate investment firms and use tax-related social engineering, especially W-8BEN update themes, to lure recipients to counterfeit authentication pages. Observed campaigns have included impersonation of firms such as Swissquote and Questrade. The actor uses phishing infrastructure associated with attacker-controlled domains and multiple phishing kits, including at least one kit assessed to be developed by the actor. Observed targeting has included users in Canada, Australia, Singapore, Switzerland, Japan, and the United States. The actor’s victimology and lure themes indicate a focus on the financial sector, especially investment services and related account holders. TA2730 is associated with credential theft and spoofing-based initial access activity rather than ransomware or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential phishing group conducting tax-themed campaigns that impersonate investment firms and direct victims to fake login pages to steal credentials for financial gain.
Credential phishing actor conducting opportunistic campaigns themed around tax forms such as W-8BEN to steal credentials for investment-related financial accounts for financial gain.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.