
Regional Threats, Global Impact: A TA2725 Case Study
Hello to all our Cyber Pals! Guest host Sarah Sabotka sits down with Senior Threat Researcher Jared Peck to unpack one of the most dynamic and persistent cybercrime groups operating today: TA2725, also known as “Grana.”
From its roots in Latin America to its global reach, TA2725 stands out for its adaptability—and its relentless pursuit of financial gain. Jared shares how the group evolved from a high-volume malware operator into a multifaceted threat actor running phishing, fraud, and malware campaigns simultaneously. The conversation dives into how Grana targets regions like Brazil and Mexico, why their tactics shift across geographies, and what makes their operations uniquely complex.
You’ll also hear:
- How threat actors “graduate” to official TA designations (and why it’s a big win for researchers)
- The impact of law enforcement disruptions on major malware operations like Grandoreiro
- Why Latin America’s banking infrastructure shapes cybercrime tactics differently
- The rise (and fall) of RMM tools in TA2725’s playbook
- What clues reveal whether activity comes from one group—or an entire cybercrime “service” ecosystem
Whether you’re in cybersecurity or just curious about how modern cybercrime operates, this episode offers a fascinating look at a threat actor that refuses to stay in one lane—and what that means for organizations worldwide.
For more information about Proofpoint, check out our website.
Subscribe & Follow:
Stay ahead of emerging threats, and subscribe! Happy hunting!
Fler avsnitt från "DISCARDED: Tales From the Threat Research Trenches"



Missa inte ett avsnitt av “DISCARDED: Tales From the Threat Research Trenches” och prenumerera på det i GetPodcast-appen.








