Russia-linked APT TAG-110 uses targets Europe and Asia

Share:

Russia-linked threat actors TAG-110 employed custom malware HATVIBE and CHERRYSPY to target organizations in Asia and Europe.

Insikt Group researchers uncovered an ongoing cyber-espionage campaign by Russia-linked threat actor TAG-110 that employed custom malware tools HATVIBE and CHERRYSPY.

The campaign primarily targeted government entities, human rights groups, and educational institutions in Central Asia, East Asia, and Europe.

The researchers pointed out that the campaign’s tactics, techniques and procedures align with the historical operations of UAC-0063, attributed to Russian APT APT28 (aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, and STRONTIUM).

The APT used HATVIBE loader to deliver malware like CHERRYSPY, threat actors often rely on malicious emails or exploited web vulnerabilities. HATVIBE uses obfuscation (e.g., XOR encryption) and persists via scheduled tasks with mshta.exe. The loader communicates with C2 servers via HTTP PUT, sharing system details.

CHERRYSPY, a Python backdoor, enables encrypted data exfiltration using RSA and AES. Used by TAG-110, it targets government and research entities to extract sensitive data and monitor systems.

“HATVIBE functions as a loader to deploy CHERRYSPY, a Python backdoor used for data exfiltration and espionage. Initial access is often achieved through phishing emails or exploiting vulnerable web-facing services like Rejetto HTTP File Server.” reads the report published by Insikt Group.

In May 2023, the Computer Emergency Response Team of Ukraine (CERT-UA) warned of a cyberespionage campaign targeting state bodies as part of an espionage campaign conducted by a threat actor tracked as UAC-0063. The attackers employed both CHERRYSPY and HATVIBE, along with the keylogger LOGPIE and STILLARCH malware.

The nation-state actor, on April 18, 2023 and April 20, 2023, sent spear-phishing emails to the department’s e-mail address, supposedly from the official mailbox of the Embassy of Tajikistan in Ukraine.

Since July 2024, TAG-110 targeted at least 62 victims across eleven countries, with notable incidents in Kazakhstan, Kyrgyzstan, and Uzbekistan.

Russia-linked APT TAG-110 uses targets Europe and Asia 1

TAG-110’s operations align with Russia’s geopolitical interests, focusing on Central Asia to maintain influence amid strained relations. The researchers pointed out that intelligence gathered in these campaigns supports Russia’s military strategies and enhances understanding of regional dynamics.

“TAG-110 is expected to continue its cyber-espionage campaigns, focusing on post-Soviet Central Asian states, Ukraine, and Ukraine’s allies. These regions are significant to Moscow due to strained relations following Russia’s invasion of Ukraine.” concludes the report. “While TAG-110’s ties to BlueDelta remain unconfirmed, its activities align with BlueDelta’s strategic interests in national security, military operations, and geopolitical influence.”

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:24 am, Jun 15, 2025
weather icon 18°C
L: 17° | H: 19°
broken clouds
Humidity: 72 %
Pressure: 1021 mb
Wind: 11 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:19 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 19°°C 0 mm 0% 12 mph 74 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 9 mph 85 % 1028 mb 0 mm/h
Tue Jun 17 10:00 pm
weather icon
16° | 26°°C 0 mm 0% 10 mph 83 % 1027 mb 0 mm/h
Wed Jun 18 10:00 pm
weather icon
15° | 27°°C 0 mm 0% 7 mph 76 % 1026 mb 0 mm/h
Thu Jun 19 10:00 pm
weather icon
17° | 28°°C 0 mm 0% 10 mph 76 % 1027 mb 0 mm/h
Today 10:00 am
weather icon
17° | 18°°C 0 mm 0% 9 mph 73 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
19° | 21°°C 0 mm 0% 9 mph 66 % 1021 mb 0 mm/h
Today 4:00 pm
weather icon
22° | 24°°C 0 mm 0% 11 mph 50 % 1022 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 21°°C 0 mm 0% 12 mph 54 % 1023 mb 0 mm/h
Today 10:00 pm
weather icon
17° | 17°°C 0 mm 0% 8 mph 74 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 15°°C 0 mm 0% 5 mph 84 % 1027 mb 0 mm/h
Tomorrow 4:00 am
weather icon
14° | 14°°C 0 mm 0% 3 mph 85 % 1027 mb 0 mm/h
Tomorrow 7:00 am
weather icon
16° | 16°°C 0 mm 0% 3 mph 76 % 1028 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,187.46
0.30%
Ethereum(ETH)
€2,184.73
-0.39%
Tether(USDT)
€0.87
-0.01%
XRP(XRP)
€1.86
-1.09%
Solana(SOL)
€125.85
-0.18%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.151589
-0.78%
Shiba Inu(SHIB)
€0.000010
-0.94%
Pepe(PEPE)
€0.000010
-0.01%
Scroll to Top