Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TA2723

Also known as: tracked as, Aug 5, Storm-2372, UNK_AcademicFlare, UTA0304, UTA032, UTA0355, BokBot

Description

TA2723 is a financially-motivated, high-volume credential phishing threat actor known for spoofing Microsoft OneDrive, LinkedIn, and DocuSign. Proofpoint Threat Research has observed TA2723 conducting OAuth device code phishing campaigns, utilizing tools like Squarephish and Graphish to enhance their operations. The use of these tools allows TA2723 to mitigate the short-lived nature of device codes, facilitating larger campaigns. Successful attacks can lead to M365 account takeover, data exfiltration, and lateral movement.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Manufacturing
Transportation
Education
Think tank
Energy
Hospitality
Healthcare

Targeted Countries / Regions

BR
MX
IR
CN
RU
UA
US

AI Analysis

· 1 week ago

Executive Summary

TA2723 is a financially motivated threat actor known for conducting high-volume credential phishing campaigns via spoofing Microsoft OneDrive, LinkedIn, and DocuSign. Utilizing tools like Squarephish and Graphish, TA2723 executes OAuth device code phishing to mitigate the short-lived nature of device codes, enabling larger and more enduring campaigns. Their operations can lead to M365 account takeovers, data exfiltration, and lateral movement within targeted networks.

Goals & Targeting

TA2723's primary goal appears to be the theft of sensitive corporate and personal credentials for financial gain. The threat actor specifically targets sectors with high-value assets, including technology, professional services, and finance, where access to M365 accounts can provide lucrative opportunities for credential trafficking or further malicious activities such as data exfiltration or fraud. Their choice of targeted countries likely reflects regions with significant business operations or where victims are more susceptible to social engineering tactics.

Enhanced Description

TA2723 is a sophisticated financially motivated threat actor specializing in credential phishing. The group has demonstrated the ability to spoof major services such as Microsoft OneDrive, LinkedIn, and DocuSign, leveraging social engineering tactics to deceive victims. TA2723's operations are characterized by their use of advanced tools like Squarephish and Graphish, which enable them to extend the lifespan of OAuth device codes. This technique allows TA2723 to conduct large-scale campaigns while overcoming limitations inherent in short-lived authentication tokens. Successful attacks result in M365 account takeovers, leading to potential data exfiltration and lateral movement within compromised networks. TA2723's targeting approach underscores a focus on sectors with high-value credentials and sensitive information, reflecting their financial motivation. Their ability to evolve their toolset highlights a level of technical sophistication that poses significant risks to targeted organizations.

Key Capabilities

  • Credential phishing via OAuth device code exploitation
  • Spoofing legitimate services (OneDrive, LinkedIn, DocuSign)
  • Use of custom tools like Squarephish and Graphish
  • Ability to extend credential lifespan through tooling
  • High-volume campaign operations

MITRE ATT&CK Tactics

Credential Access
Persistence
Exfiltration
Impact

ATT&CK Techniques

T1563.001 -Credential Phishing
T1554.002 - OAuth Device Code Harvesting
T1554.004 - Exploitation of Third-Party APIs
T1055 - Internal Spear-Phishing

Software / Tooling

Squarephish
Graphish
Custom credential phishing tools

Campaigns & Victims

TA2723 operates with a high-volume, targeted approach, focusing on businesses and professionals who use Microsoft 365 services. Campaigns are typically long-term, leveraging their ability to extend device code lifespans through specialized tools. This enables sustained access to victim accounts even when initial phishing attempts may be detected. Notable past operations include multiple waves of credential phishing campaigns across various industries, leading to compromises in financial and professional sectors.

IOC Patterns

  • Spear-phishing emails impersonating Microsoft OneDrive, LinkedIn, or DocuSign
  • Use of OAuth device code authentication flows
  • Landing pages mimicking legitimate service logins
  • Network traffic originating from known TA2723 infrastructure
  • Presence of Squarephish or Graphish signatures in email payloads

Recommended Actions

  • Implement multi-factor authentication for Microsoft 365 accounts
  • Educate employees about phishing tactics and OAuth device code exploitation
  • Monitor for unusual login patterns and suspicious account activity
  • Use email filtering to detect and block spear-phishing attempts
  • Conduct regular security audits of M365 credentials

Suggested Tags

Financially Motivated
Credential Phishing
APTPersistence
Cloud Services APT
Fraudulent Activities

Confidence Assessment

The confidence level in the available data on TA2723 is moderately high, given the detailed observations regarding their TTPs and toolset. However, there are gaps in understanding their exact origin, specific campaign timelines, and potential long-term strategic goals beyond credential theft. Further intelligence sharing and deeper analysis of their infrastructure would enhance confidence in this assessment.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 5 Domain 13 URL 1 Email Address 1

References

  1. www.microsoft.com — Cited by web research for: STOP
  2. www.proofpoint.com — Cited by web research for: Graphish
  3. www.proofpoint.com — Cited by web research for: Global
  4. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  5. www.bleepingcomputer.com — Cited by web research for: Dark

Intel Summary

0

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Data Exfiltration
Financially Motivated
Credential Phishing
APTPersistence
Cloud Services APT
Fraudulent Activities

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.