TA2725 is a financially motivated cybercriminal threat actor tracked since 2022 that primarily targets organizations and users in Brazil, Mexico, and Spain. The actor is associated with credential phishing and the delivery of Brazilian banking malware, including Mispadu, Astaroth, and historically Grandoreiro. Its operations have focused on theft of banking credentials, as well as consumer credentials and payment information associated with online services. TA2725 commonly uses phishing emails and socially engineered lures such as tax, billing, utility, and shared-document themes. Campaigns have used URL redirectors and cloud-hosted archives to deliver compressed payloads containing loaders and malware. In Grandoreiro-related activity, delivery chains have involved archive files containing MSI, HTA, or executable loaders that use DLL injection to execute the final payload. Associated malware families used by this actor support credential theft through banking overlays and can also enable keylogging and screen capture. The actor has demonstrated cross-regional targeting, including simultaneous campaigns against Mexico and Spain in 2023 using shared infrastructure and payloads. In that activity, Grandoreiro builds were updated to include banking credential theft overlays for institutions in both countries within the same malware version, reflecting operational adaptation beyond the actor’s earlier concentration on Latin America. TA2725 has also used brand spoofing in phishing campaigns to increase credibility. In 2025, TA2725 expanded its tooling by delivering the legitimate remote monitoring and management product ScreenConnect in campaigns targeting organizations in Mexico, indicating an evolution toward abuse of commercial remote-access software for initial access and follow-on intrusion activity. Overall, TA2725 is best characterized as a Latin America-focused cybercriminal actor specializing in phishing-led credential theft and banking malware operations, with growing flexibility in payload selection and geographic targeting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another actor observed using a rare social-engineering lure technique (customized photo of purported physical mail showing recipient name/address). No additional operational details provided in this content.
Cybercriminal threat actor known for Brazilian banking malware and credential phishing; expanded to delivering ScreenConnect as a first-stage payload in campaigns targeting Mexico.
Uses Brazilian banking malware and phishing to target organizations and users, primarily in Brazil and Mexico, and more recently Spain. The group delivers Grandoreiro to steal banking credentials, consumer credentials, and payment information, including for Netflix and Amazon accounts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.