Also known as: tracked as, Aug 5, Storm-2372, UNK_AcademicFlare, UTA0304, UTA032, UTA0355, BokBot
TA2723 is a financially-motivated, high-volume credential phishing threat actor known for spoofing Microsoft OneDrive, LinkedIn, and DocuSign. Proofpoint Threat Research has observed TA2723 conducting OAuth device code phishing campaigns, utilizing tools like Squarephish and Graphish to enhance their operations. The use of these tools allows TA2723 to mitigate the short-lived nature of device codes, facilitating larger campaigns. Successful attacks can lead to M365 account takeover, data exfiltration, and lateral movement.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TA2723 is a financially motivated threat actor known for conducting high-volume credential phishing campaigns via spoofing Microsoft OneDrive, LinkedIn, and DocuSign. Utilizing tools like Squarephish and Graphish, TA2723 executes OAuth device code phishing to mitigate the short-lived nature of device codes, enabling larger and more enduring campaigns. Their operations can lead to M365 account takeovers, data exfiltration, and lateral movement within targeted networks.
Goals & Targeting
TA2723's primary goal appears to be the theft of sensitive corporate and personal credentials for financial gain. The threat actor specifically targets sectors with high-value assets, including technology, professional services, and finance, where access to M365 accounts can provide lucrative opportunities for credential trafficking or further malicious activities such as data exfiltration or fraud. Their choice of targeted countries likely reflects regions with significant business operations or where victims are more susceptible to social engineering tactics.
Enhanced Description
TA2723 is a sophisticated financially motivated threat actor specializing in credential phishing. The group has demonstrated the ability to spoof major services such as Microsoft OneDrive, LinkedIn, and DocuSign, leveraging social engineering tactics to deceive victims. TA2723's operations are characterized by their use of advanced tools like Squarephish and Graphish, which enable them to extend the lifespan of OAuth device codes. This technique allows TA2723 to conduct large-scale campaigns while overcoming limitations inherent in short-lived authentication tokens. Successful attacks result in M365 account takeovers, leading to potential data exfiltration and lateral movement within compromised networks. TA2723's targeting approach underscores a focus on sectors with high-value credentials and sensitive information, reflecting their financial motivation. Their ability to evolve their toolset highlights a level of technical sophistication that poses significant risks to targeted organizations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA2723 operates with a high-volume, targeted approach, focusing on businesses and professionals who use Microsoft 365 services. Campaigns are typically long-term, leveraging their ability to extend device code lifespans through specialized tools. This enables sustained access to victim accounts even when initial phishing attempts may be detected. Notable past operations include multiple waves of credential phishing campaigns across various industries, leading to compromises in financial and professional sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on TA2723 is moderately high, given the detailed observations regarding their TTPs and toolset. However, there are gaps in understanding their exact origin, specific campaign timelines, and potential long-term strategic goals beyond credential theft. Further intelligence sharing and deeper analysis of their infrastructure would enhance confidence in this assessment.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics