Die mit Russland verbundene APT TAG-110 zielt auf Europa und Asien ab

Teilen:

Russia-linked threat actors TAG-110 employed custom malware HATVIBE and CHERRYSPY to target organizations in Asia and Europe.

Insikt Group researchers uncovered an ongoing cyber-espionage campaign by Russia-linked threat actor TAG-110 that employed custom malware tools HATVIBE and CHERRYSPY.

The campaign primarily targeted government entities, human rights groups, and educational institutions in Central Asia, East Asia, and Europe.

The researchers pointed out that the campaign’s tactics, techniques and procedures align with the historical operations of UAC-0063, attributed to Russian APT APT28 (aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, and STRONTIUM).

The APT used HATVIBE loader to deliver malware like CHERRYSPY, threat actors often rely on malicious emails or exploited web vulnerabilities. HATVIBE uses obfuscation (e.g., XOR encryption) and persists via scheduled tasks with mshta.exe. The loader communicates with C2 servers via HTTP PUT, sharing system details.

CHERRYSPY, a Python backdoor, enables encrypted data exfiltration using RSA and AES. Used by TAG-110, it targets government and research entities to extract sensitive data and monitor systems.

“HATVIBE functions as a loader to deploy CHERRYSPY, a Python backdoor used for data exfiltration and espionage. Initial access is often achieved through phishing emails or exploiting vulnerable web-facing services like Rejetto HTTP File Server.” reads the report published by Insikt Group.

In May 2023, the Computer Emergency Response Team of Ukraine (CERT-UA) warned of a cyberespionage campaign targeting state bodies as part of an espionage campaign conducted by a threat actor tracked as UAC-0063. The attackers employed both CHERRYSPY and HATVIBE, along with the keylogger LOGPIE and STILLARCH malware.

The nation-state actor, on April 18, 2023 and April 20, 2023, sent spear-phishing emails to the department’s e-mail address, supposedly from the official mailbox of the Embassy of Tajikistan in Ukraine.

Since July 2024, TAG-110 targeted at least 62 victims across eleven countries, with notable incidents in Kazakhstan, Kyrgyzstan, and Uzbekistan.

Russia-linked APT TAG-110 uses targets Europe and Asia 1

TAG-110’s operations align with Russia’s geopolitical interests, focusing on Central Asia to maintain influence amid strained relations. The researchers pointed out that intelligence gathered in these campaigns supports Russia’s military strategies and enhances understanding of regional dynamics.

“TAG-110 is expected to continue its cyber-espionage campaigns, focusing on post-Soviet Central Asian states, Ukraine, and Ukraine’s allies. These regions are significant to Moscow due to strained relations following Russia’s invasion of Ukraine.” concludes the report. “While TAG-110’s ties to BlueDelta remain unconfirmed, its activities align with BlueDelta’s strategic interests in national security, military operations, and geopolitical influence.”

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:06 pm, Apr. 22, 2025
Wetter-Symbol 15°C
L: 14° | H: 16°
broken clouds
Luftfeuchtigkeit: 56 %
Druck: 1017 mb
Wind: 9 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 80%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:49 am
Sonnenuntergang: 8:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 16°°C 0 mm 0% 11 mph 76 % 1017 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
8° | 11°°C 1 mm 100% 12 mph 94 % 1018 mb 0 mm/h
Do. Apr. 24 10:00 pm
Wetter-Symbol
8° | 16°°C 0.71 mm 71% 5 mph 91 % 1023 mb 0 mm/h
Fr. Apr. 25 10:00 pm
Wetter-Symbol
8° | 17°°C 0.2 mm 20% 7 mph 90 % 1023 mb 0 mm/h
Sa. Apr. 26 10:00 pm
Wetter-Symbol
11° | 18°°C 1 mm 100% 7 mph 98 % 1023 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
15° | 16°°C 0 mm 0% 8 mph 56 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 10 mph 51 % 1017 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 11 mph 56 % 1016 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
10° | 10°°C 0 mm 0% 7 mph 76 % 1016 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 7 mph 77 % 1014 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
9° | 9°°C 1 mm 100% 10 mph 94 % 1012 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
8° | 8°°C 1 mm 100% 11 mph 93 % 1011 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
8° | 8°°C 1 mm 100% 9 mph 93 % 1012 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€76,823.87
1.36%
Ethereum(ETH)
€1,412.77
-0.41%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.82
-1.18%
Solana(SOL)
€121.33
-0.13%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.142601
1.46%
Shiba Inu(SHIB)
€0.000011
-1.05%
Pepe(PEPE)
€0.000007
2.57%
Nach oben scrollen