Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ta2730

Also known as: tracked as

Description

TA2730’s operations are characterized by opportunistic phishing campaigns that exploit current events—most recently the SpaceX IPO—to attract victims from a broad range of jurisdictions. The group's emails typically pose as investment firms or financial platforms, including references to Elon Musk and prominent brokers such as Fidelity or Robinhood. Recipients receive messages requesting updates to W‑8BEN tax forms for non‑U.S. investors; the links lead to sophisticated imitation sites that mimic real account portals. These custom landing pages capture login credentials before redirecting users to a cryptocurrency wallet, where victims are prompted to transfer funds in Bitcoin, Ethereum, or USDT.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Energy
Hospitality

Targeted Countries / Regions

JP
CA
AU
SG
US
TR
MX
ES
CN
KP
IN
TW
IT

AI Analysis

Grounded in web research
· 8 hours ago

Executive Summary

TA2730 is a financially motivated threat actor that operates primarily through phishing and social engineering attacks targeting the financial services industry across a wide geographic footprint, including Japan, Canada, Australia, Singapore, the United States, Turkey, Mexico, Spain, China, North Korea, India, Taiwan, and Italy. The actor recently leveraged high-profile public interest in SpaceX’s IPO by creating counterfeit investment portals that imitate reputable entities such as Elon Musk and major brokerage brands, using legitimate-looking W‑8BEN tax forms to lure victims into providing credentials and directing them to cryptocurrency wallets for direct theft. While earlier campaigns focused on credential harvesting via phishing landing pages, the latest iteration seeks immediate financial gain through crypto payouts.

Goals & Targeting

The actor’s strategic objective is rapid monetization through direct cash outflows rather than long‑term credential exploitation. By targeting financial institutions—especially brokerage and investment firms—as well as individuals handling cross‑border securities, TA2730 exploits the high-value nature of client portfolios and the trust associated with regulated entities. The chosen sectors (financial services, government, defense, energy, hospitality) span organizations that manage substantial assets or have routine exposure to tax documentation, allowing the actor to broaden its attack surface while maintaining plausible deniability.

Enhanced Description

Key Capabilities

  • Sophisticated email spoofing and domain registration
  • Creation of convincing phishing landing pages with customized branding
  • Use of legitimate tax‑form lures (W-8BEN, W-2, W-9) to increase credibility
  • Exfiltration of user credentials via credential harvesting scripts
  • Transfer of stolen funds through cryptocurrency wallets for rapid laundering
  • Multinational targeting spanning over a dozen countries
  • Rapid campaign deployment and short operational cycles

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Exfiltration
Command & Control

ATT&CK Techniques

T1566.001 - Phishing (Spearphishing Link)
T1204.002 - User Execution: Malicious File
T1078.004 - Valid Accounts: Default Accounts
T1110.001 - Brute Force: Password Guessing
T1005 - Data from Local System
T1059.003 - Command and Scripting Interpreter: PowerShell
T1105 - Remote File Copy

Software / Tooling

Pikabot
Satori
Qbot
Impacket
Phishing kits (generic)

Campaigns & Victims

TA2730 prefers opportunistic, low‑profile campaigns rather than long‑term APT‑style operations, delivering messages en masse to a broad audience with minimal customizations beyond the geographic focus. The actor consistently uses tax‑form lures in both English and localized languages, embedding legitimate phone numbers for authenticity. They rotate domain names frequently and use short lifespans—typically days—to avoid detection. The June 2025‑March 2026 window saw multiple coordinated campaigns across Canada, Switzerland, and the U.S., all converging on a single phishing framework that harvests credentials before diverting victims to crypto wallets.

IOC Patterns

  • Spear‑phishing emails impersonating investment firms
  • Embedded W-8BEN or other tax‑form lures
  • Randomized domain names mimicking SpaceX branding
  • Redirects to cryptocurrency wallet addresses after login capture
  • Use of legitimate phone numbers and support links for credibility

Recommended Actions

  • Implement multi‑factor authentication on all financial portals.
  • Block known malicious domains and IP ranges associated with phishing campaigns.
  • Enforce strict email authentication (SPF, DKIM, DMARC) to detect spoofing.
  • Deploy web security gateways to flag suspicious URLs and blocked destinations such as cryptocurrency wallet sites.
  • Educate employees about tax‑form lures and verification procedures for unsolicited requests.
  • Maintain up‑to‑date threat intelligence feeds focused on phishing domains and IOC signatures.

Suggested Tags

financial fraud
phishing
credential theft
cryptocurrency theft
tax form lure
multi‑national threat

Confidence Assessment

The information is supported by a credible Proofpoint research blog detailing TA2730’s phishing tactics, tax‑form lures, and geographic reach. While the recent SpaceX IPO‑based campaign is described in secondary reports, specific attribution of tool families remains inferred from linked indicators rather than direct sightings. Key gaps include exact infrastructure timelines, internal operational procedures, and verified malware samples.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Email Address 18 URL 1 IPv4 Address 1

References

  1. www.proofpoint.com — Cited by web research for: Payload
  2. www.proofpoint.com — Cited by web research for: Impacket
  3. ministang.com — Cited by web research for: curl
  4. cyberpress.org — Cited by web research for: WhatsApp
  5. www.infosecurity-magazine.com — Cited by web research for: Hospitality

Intel Summary

7

Techniques

35

Tools

0

Campaigns

76

IOCs

0

Observed Data

1

Tactics

Tags

Financial Targeting
Phishing
Fraud
Financial-Sector
Investment-Fraud
Cryptocurrency-Threat
financial fraud
phishing
credential theft
cryptocurrency theft
tax form lure
multi‑national threat

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
55%
Added
Jul 15, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.