Skip to main content
Mallory
1 malware family

TA2726

Also known asTA2726

TA2726 is a financially motivated threat actor cluster assessed to function primarily as a traffic provider or traffic distribution service for other threat actors. Reporting links TA2726 to operation of Parrot TDS and abuse of Keitaro TDS/Keitaro Tracker, including use of stolen or cracked Keitaro licenses. TA2726 has been described as compromising websites and injecting Keitaro TDS links, then selling or brokering that traffic to customers including other malware actors. The cluster is specifically linked to supporting SocGholish/FakeUpdates and TA2727. Multiple reports state that TA2726 functioned as a traffic provider for SocGholish and TA2727 by compromising websites and injecting Keitaro TDS links for resale. Proofpoint assessed that TA2726 may act as a traffic distribution service for other threat actors, and that TA2726 and TA2727 were both involved in web-inject campaigns using fake browser update lures. TA2726 and TA2727 have both been linked to fake browser updates as an attack vector, and FrigidStealer activity has been linked to both clusters. Observed tactics and tradecraft directly mentioned in the reporting include use of traffic distribution systems, website compromise, malicious web injects, fake browser update lures, and traffic brokering/resale. TA2726 is also described as operating infrastructure used to route victims to downstream malicious activity. Content does not directly attribute malware development to TA2726; rather, the high-confidence characterization is that it provides and monetizes traffic and redirection infrastructure used by other actors. Known alias in the provided content: TA2726.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

ARSENAL

Associated malware families

1 malware family attributed to this actor across reporting.

IOCS

Observables

22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables22

Domains, IPs, and hashes tied to this actor, refreshed continuously.