TA2722

Aliases: Balikbayan Foxes

Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:13:30

Targeted industries: transportation-and-logistics manufacturing professional-services healthcare-and-pharmaceutical energy-and-utilities

Targeted regions: country_code:us country_code:ca country_code:gb country_code:de country_code:ph

Context

TA2722 is a highly active threat actor that targets various industries including Shipping/Logistics, Manufacturing, Business Services, Pharmaceutical, and Energy. They primarily focus on organizations in North America, Europe, and Southeast Asia. This threat actor impersonates Philippine government entities and uses themes related to the government to gain remote access to target computers. Their objectives include information gathering, installing follow-on malware, and engaging in business email compromise activities.

Reports & references

  • proofpoint.com — New Threat Actor Spoofs Philippine Government Covid 19 Health Data Widespread (report)

External references