Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
2 malware families

TA2726

Also known asTA2726

TA2726 is a financially motivated cybercriminal threat actor tracked by Proofpoint that operates as a malicious traffic distribution service (TDS) provider for other threat actors. Proofpoint assesses with high confidence that TA2726 acts as a traffic distribution service for both TA569 and TA2727, and has been active since at least September 2022. TA2726 appears to function as a traffic seller and likely handles webserver or website compromises that enable malicious injects used by other actors. TA2726 is repeatedly associated with abuse of Keitaro TDS, including operation of a malicious Keitaro-based service and use of illicit, stolen, or cracked Keitaro licenses. Reporting links TA2726 to compromised websites where highly obfuscated JavaScript or Keitaro TDS links are injected, after which victims are filtered and redirected by geography, browser, device type, IP, and other criteria. Proofpoint reported that in observed 2025 activity, TA2726 redirected North American traffic to TA569’s SocGholish/FakeUpdates infection chain, while traffic from other regions was routed to TA2727 campaigns. TA2726 has been described as a traffic provider for SocGholish and TA2727, including by compromising websites and injecting Keitaro TDS links for resale. In TA569-related chains, TA2726 operated a malicious Keitaro service used to route users into SocGholish delivery, and reporting states TA2726 injected highly obfuscated JavaScript into compromised sites through a fake WordPress plugin that ultimately loaded SocGholish code. TA2726 infrastructure has also been observed delivering traffic for TA2727, whose campaigns used fake browser update lures to distribute malware including Lumma Stealer, DeerStealer, Marcher, and FrigidStealer. Known aliases directly reflected in the content are limited to TA2726.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics9 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1189×2
Drive-by Compromise
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
T1059.007
JavaScript
TA0003
Persistence
2 techniques
T1205×5
Traffic Signaling
T1505
Server Software Component
TA0005
Stealth
2 techniques
T1027×2
Obfuscated Files or Information
T1205×5
Traffic Signaling
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0011
Command and Control
1 technique
T1205×5
Traffic Signaling
IOCS

Observables

24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping6

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables24

Domains, IPs, and hashes tied to this actor, refreshed continuously.

TA2726 | Mallory