Russia-Aligned TAG-110 Targets Tajikistan with Macro-Enabled
3 Articles
3 Articles
TAG-110 Hackers Deploy Malicious Word Templates In Targeted Attacks - Cybernoz - Cybersecurity News
The Russia-aligned threat actor TAG-110, also linked to UAC-0063 and APT28 (BlueDelta) with medium confidence by CERT-UA, has shifted tactics to target government, educational, and research entities in Tajikistan. According to analysis by Insikt Group from Recorded Future Report, TAG-110 has moved away from its traditional use of HTA-based payloads like HATVIBE, which it has employed since at least 2023, to leveraging macro-enabled Microsoft Wor…
Russia-Aligned TAG-110 Targets Tajikistan with Macro-Enabled
Note: The analysis cut-off date for this report was March 24, 2025.Executive SummaryFrom January to February 2025, Insikt Group detected a phishing campaign targeting Tajikistan that Insikt Group attributes to TAG-110, a Russia-aligned threat actor that overlaps with UAC-0063 and has been linked to APT28 (BlueDelta) with medium confidence by CERT-UA. In this campaign, TAG-110 leveraged Tajikistan government-themed documents as lure material, con…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage