Russia-linked APT TAG-110 uses targets Europe and Asia

Share:

Russia-linked threat actors TAG-110 employed custom malware HATVIBE and CHERRYSPY to target organizations in Asia and Europe.

Insikt Group researchers uncovered an ongoing cyber-espionage campaign by Russia-linked threat actor TAG-110 that employed custom malware tools HATVIBE and CHERRYSPY.

The campaign primarily targeted government entities, human rights groups, and educational institutions in Central Asia, East Asia, and Europe.

The researchers pointed out that the campaign’s tactics, techniques and procedures align with the historical operations of UAC-0063, attributed to Russian APT APT28 (aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, and STRONTIUM).

The APT used HATVIBE loader to deliver malware like CHERRYSPY, threat actors often rely on malicious emails or exploited web vulnerabilities. HATVIBE uses obfuscation (e.g., XOR encryption) and persists via scheduled tasks with mshta.exe. The loader communicates with C2 servers via HTTP PUT, sharing system details.

CHERRYSPY, a Python backdoor, enables encrypted data exfiltration using RSA and AES. Used by TAG-110, it targets government and research entities to extract sensitive data and monitor systems.

“HATVIBE functions as a loader to deploy CHERRYSPY, a Python backdoor used for data exfiltration and espionage. Initial access is often achieved through phishing emails or exploiting vulnerable web-facing services like Rejetto HTTP File Server.” reads the report published by Insikt Group.

In May 2023, the Computer Emergency Response Team of Ukraine (CERT-UA) warned of a cyberespionage campaign targeting state bodies as part of an espionage campaign conducted by a threat actor tracked as UAC-0063. The attackers employed both CHERRYSPY and HATVIBE, along with the keylogger LOGPIE and STILLARCH malware.

The nation-state actor, on April 18, 2023 and April 20, 2023, sent spear-phishing emails to the department’s e-mail address, supposedly from the official mailbox of the Embassy of Tajikistan in Ukraine.

Since July 2024, TAG-110 targeted at least 62 victims across eleven countries, with notable incidents in Kazakhstan, Kyrgyzstan, and Uzbekistan.

Russia-linked APT TAG-110 uses targets Europe and Asia 1

TAG-110’s operations align with Russia’s geopolitical interests, focusing on Central Asia to maintain influence amid strained relations. The researchers pointed out that intelligence gathered in these campaigns supports Russia’s military strategies and enhances understanding of regional dynamics.

“TAG-110 is expected to continue its cyber-espionage campaigns, focusing on post-Soviet Central Asian states, Ukraine, and Ukraine’s allies. These regions are significant to Moscow due to strained relations following Russia’s invasion of Ukraine.” concludes the report. “While TAG-110’s ties to BlueDelta remain unconfirmed, its activities align with BlueDelta’s strategic interests in national security, military operations, and geopolitical influence.”

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:00 am, Apr 22, 2025
weather icon 6°C
L: 5° | H: 7°
overcast clouds
Humidity: 91 %
Pressure: 1015 mb
Wind: 2 mph WNW
Wind Gust: 6 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 98%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:49 am
Sunset: 8:07 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
5° | 7°°C 0 mm 0% 10 mph 92 % 1017 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
8° | 10°°C 1 mm 100% 13 mph 94 % 1018 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
8° | 13°°C 0 mm 0% 4 mph 88 % 1022 mb 0 mm/h
Fri Apr 25 10:00 pm
weather icon
10° | 17°°C 0 mm 0% 8 mph 90 % 1021 mb 0 mm/h
Sat Apr 26 10:00 pm
weather icon
10° | 17°°C 1 mm 100% 14 mph 94 % 1021 mb 0 mm/h
Today 7:00 am
weather icon
7° | 7°°C 0 mm 0% 4 mph 92 % 1015 mb 0 mm/h
Today 10:00 am
weather icon
10° | 13°°C 0 mm 0% 7 mph 77 % 1016 mb 0 mm/h
Today 1:00 pm
weather icon
16° | 16°°C 0 mm 0% 8 mph 42 % 1017 mb 0 mm/h
Today 4:00 pm
weather icon
16° | 16°°C 0 mm 0% 10 mph 44 % 1016 mb 0 mm/h
Today 7:00 pm
weather icon
13° | 13°°C 0 mm 0% 10 mph 59 % 1016 mb 0 mm/h
Today 10:00 pm
weather icon
10° | 10°°C 0 mm 0% 7 mph 77 % 1016 mb 0 mm/h
Tomorrow 1:00 am
weather icon
10° | 10°°C 0 mm 0% 7 mph 79 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
9° | 9°°C 1 mm 100% 11 mph 94 % 1011 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€76,502.79
1.07%
Ethereum(ETH)
€1,370.04
-3.50%
Tether(USDT)
€0.87
0.01%
XRP(XRP)
€1.80
-1.29%
Solana(SOL)
€120.93
-0.05%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.139525
0.25%
Shiba Inu(SHIB)
€0.000010
-1.34%
Pepe(PEPE)
€0.000007
2.74%
Scroll to Top