Also known as: tracked as
TA2730’s operations are characterized by opportunistic phishing campaigns that exploit current events—most recently the SpaceX IPO—to attract victims from a broad range of jurisdictions. The group's emails typically pose as investment firms or financial platforms, including references to Elon Musk and prominent brokers such as Fidelity or Robinhood. Recipients receive messages requesting updates to W‑8BEN tax forms for non‑U.S. investors; the links lead to sophisticated imitation sites that mimic real account portals. These custom landing pages capture login credentials before redirecting users to a cryptocurrency wallet, where victims are prompted to transfer funds in Bitcoin, Ethereum, or USDT.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TA2730 is a financially motivated threat actor that operates primarily through phishing and social engineering attacks targeting the financial services industry across a wide geographic footprint, including Japan, Canada, Australia, Singapore, the United States, Turkey, Mexico, Spain, China, North Korea, India, Taiwan, and Italy. The actor recently leveraged high-profile public interest in SpaceX’s IPO by creating counterfeit investment portals that imitate reputable entities such as Elon Musk and major brokerage brands, using legitimate-looking W‑8BEN tax forms to lure victims into providing credentials and directing them to cryptocurrency wallets for direct theft. While earlier campaigns focused on credential harvesting via phishing landing pages, the latest iteration seeks immediate financial gain through crypto payouts.
Goals & Targeting
The actor’s strategic objective is rapid monetization through direct cash outflows rather than long‑term credential exploitation. By targeting financial institutions—especially brokerage and investment firms—as well as individuals handling cross‑border securities, TA2730 exploits the high-value nature of client portfolios and the trust associated with regulated entities. The chosen sectors (financial services, government, defense, energy, hospitality) span organizations that manage substantial assets or have routine exposure to tax documentation, allowing the actor to broaden its attack surface while maintaining plausible deniability.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA2730 prefers opportunistic, low‑profile campaigns rather than long‑term APT‑style operations, delivering messages en masse to a broad audience with minimal customizations beyond the geographic focus. The actor consistently uses tax‑form lures in both English and localized languages, embedding legitimate phone numbers for authenticity. They rotate domain names frequently and use short lifespans—typically days—to avoid detection. The June 2025‑March 2026 window saw multiple coordinated campaigns across Canada, Switzerland, and the U.S., all converging on a single phishing framework that harvests credentials before diverting victims to crypto wallets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information is supported by a credible Proofpoint research blog detailing TA2730’s phishing tactics, tax‑form lures, and geographic reach. While the recent SpaceX IPO‑based campaign is described in secondary reports, specific attribution of tool families remains inferred from linked indicators rather than direct sightings. Key gaps include exact infrastructure timelines, internal operational procedures, and verified malware samples.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
35
Tools
0
Campaigns
76
IOCs
0
Observed Data
1
Tactics