TA2715 is a cybercrime threat cluster associated with phishing campaigns that deliver commodity malware, including information stealers and remote access trojans. The actor has been observed using email as a primary initial-access vector, typically relying on malicious attachments that lead to execution of the DTPacker malware packer/downloader and subsequent delivery of follow-on payloads. Reported payload families associated with DTPacker activity used by TA2715 and related actors include Agent Tesla, Ave Maria (Warzone RAT), AsyncRAT, FormBook, Snake Keylogger, and Stealerium. TA2715 has been linked to use of DTPacker since at least 2020. DTPacker is notable for combining downloader and packer functionality and for employing layered obfuscation and decoding routines intended to evade antivirus, sandboxing, and analyst scrutiny. Observed techniques include custom XOR-based decoding, character-code substitution, string obfuscation, junk Unicode insertion, and staged extraction and execution of embedded or downloaded payloads. Payload hosting and retrieval have used masquerading or themed download locations, reflecting an emphasis on defense evasion and operational flexibility. The actor’s activity is consistent with financially motivated malware distribution rather than espionage. Available reporting directly supports phishing-based malware delivery and credential-stealing tooling, but does not establish a specific national affiliation, stable victim geography, or narrowly defined sector focus for TA2715 itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
E-crime phishing campaigns delivering the Stealerium information stealer (and previously associated with Snake Keylogger), using lures impersonating charities, banks, courts, and document services.
TA2715 is another threat actor observed leveraging DTPacker to deliver various malware payloads, including RATs and information stealers. Their operations have included the use of themed download locations and advanced obfuscation techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.