TA2723TA2723

Also known as: TA2723

Known aliases
1

Profile

TA2723 is a financially-motivated, high-volume credential phishing threat actor known for spoofing Microsoft OneDrive, LinkedIn, and DocuSign. Proofpoint Threat Research has observed TA2723 conducting OAuth device code phishing campaigns, utilizing tools like Squarephish and Graphish to enhance their operations. The use of these tools allows TA2723 to mitigate the short-lived nature of device codes, facilitating larger campaigns. Successful attacks can lead to M365 account takeover, data exfiltration, and lateral movement.

Aliases· 1

TA2723

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
TA2725
Actor
TA2552
Actor
TA2722
Actor
Storm-2372
Actor
DEV-0928
Actor
TA2719
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.