TA2726
TA2726 is a financially motivated cybercriminal threat actor tracked by Proofpoint that operates as a malicious traffic distribution service (TDS) provider for other threat actors. Proofpoint assesses with high confidence that TA2726 acts as a traffic distribution service for both TA569 and TA2727, and has been active since at least September 2022. TA2726 appears to function as a traffic seller and likely handles webserver or website compromises that enable malicious injects used by other actors. TA2726 is repeatedly associated with abuse of Keitaro TDS, including operation of a malicious Keitaro-based service and use of illicit, stolen, or cracked Keitaro licenses. Reporting links TA2726 to compromised websites where highly obfuscated JavaScript or Keitaro TDS links are injected, after which victims are filtered and redirected by geography, browser, device type, IP, and other criteria. Proofpoint reported that in observed 2025 activity, TA2726 redirected North American traffic to TA569’s SocGholish/FakeUpdates infection chain, while traffic from other regions was routed to TA2727 campaigns. TA2726 has been described as a traffic provider for SocGholish and TA2727, including by compromising websites and injecting Keitaro TDS links for resale. In TA569-related chains, TA2726 operated a malicious Keitaro service used to route users into SocGholish delivery, and reporting states TA2726 injected highly obfuscated JavaScript into compromised sites through a fake WordPress plugin that ultimately loaded SocGholish code. TA2726 infrastructure has also been observed delivering traffic for TA2727, whose campaigns used fake browser update lures to distribute malware including Lumma Stealer, DeerStealer, Marcher, and FrigidStealer. Known aliases directly reflected in the content are limited to TA2726.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Observables
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a traffic distribution system operator collaborating with SocGholish/TA569 and selling or redirecting victim traffic into the SocGholish framework.
Operates a malicious Keitaro-based traffic distribution service used to inject obfuscated JavaScript into compromised sites and funnel traffic for TA569 web inject campaigns.
Associated with operating a Keitaro-based traffic distribution service used in the SocGholish infection chain to route victims.
An actor that operates a Traffic Direction System used to filter and redirect victims into the SocGholish infection chain.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.