TA2726 is a financially motivated cybercriminal threat actor that operates as a malicious traffic distribution service (TDS) and web-inject enablement layer for other malware operators. The actor has been active since at least September 2022 and is closely associated with fake browser update campaigns, compromised websites, and Keitaro-based traffic filtering and redirection. TA2726 has been assessed with high confidence as a service provider for downstream actors including TA569, the operator behind SocGholish, and TA2727, which has distributed information stealers across Windows, Android, and macOS. TA2726 specializes in converting compromised websites, especially WordPress sites, into selective malware delivery infrastructure. Its operations have included highly obfuscated JavaScript injections, fake WordPress plugins, malicious use of WordPress admin-ajax bootstrapping, and same-origin REST or query gateways that profile visitors before deciding whether to pass them to downstream payload chains. Observed workflows used multi-step eligibility checks, tokenized state transitions, and client-side and server-side filtering to evaluate operating system, browser state, geography, prior exposure, interaction patterns, and anti-analysis signals such as automation artifacts or developer-tool usage. Eligible Windows users were routed into TA569’s SocGholish fake browser update chain, which in turn delivered GhoLoader and additional follow-on malware. The actor is strongly linked to abuse of the Keitaro traffic distribution platform, including operation of a malicious Keitaro-based service and use of illicit copies of the tracker. TA2726 has been described as a traffic seller that compromises websites, injects TDS links, and resells filtered victim traffic to customers. Reporting also ties TA2726 to ParrotTDS-style delivery chains and to broader criminal abuse of TDS infrastructure for malware delivery, cryptocurrency theft, and scam monetization. TA2726 is part of a broader web-inject ecosystem that became more crowded and collaborative from 2023 onward, with multiple actors reusing similar fake update lures and shared infrastructure patterns. Proofpoint separated TA2726 from activity previously grouped under SocGholish, identifying it as the traffic-distribution component rather than the final malware operator. The actor has also been linked to website compromises that later carried additional monetization layers such as ClickFix-style injections. TA2726’s role in the ecosystem is best understood as an intermediary access-and-traffic broker that enables initial access and malware delivery for partner threat actors rather than as a standalone malware family operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named cybercriminal activity cluster referenced because Shady Squirrel reacquired domains previously associated with it.
Previously operated malicious domains later acquired by Stuffy Squirrel and Shady Squirrel; also referenced as sharing cookie patterns seen in Keitaro-related activity.
Operates a compromised-WordPress traffic distribution and visitor-gating layer that turns legitimate sites into malware delivery infrastructure, filtering visitors and handing selected users to downstream malware operators. The same infected hosts were later observed carrying ClickFix injections using EtherHiding.
Named as a traffic distribution system operator collaborating with SocGholish/TA569 and selling or redirecting victim traffic into the SocGholish framework.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.