Russia-linked APT TAG-110 uses targets Europe and Asia

Share:

Russia-linked threat actors TAG-110 employed custom malware HATVIBE and CHERRYSPY to target organizations in Asia and Europe.

Insikt Group researchers uncovered an ongoing cyber-espionage campaign by Russia-linked threat actor TAG-110 that employed custom malware tools HATVIBE and CHERRYSPY.

The campaign primarily targeted government entities, human rights groups, and educational institutions in Central Asia, East Asia, and Europe.

The researchers pointed out that the campaign’s tactics, techniques and procedures align with the historical operations of UAC-0063, attributed to Russian APT APT28 (aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, and STRONTIUM).

The APT used HATVIBE loader to deliver malware like CHERRYSPY, threat actors often rely on malicious emails or exploited web vulnerabilities. HATVIBE uses obfuscation (e.g., XOR encryption) and persists via scheduled tasks with mshta.exe. The loader communicates with C2 servers via HTTP PUT, sharing system details.

CHERRYSPY, a Python backdoor, enables encrypted data exfiltration using RSA and AES. Used by TAG-110, it targets government and research entities to extract sensitive data and monitor systems.

“HATVIBE functions as a loader to deploy CHERRYSPY, a Python backdoor used for data exfiltration and espionage. Initial access is often achieved through phishing emails or exploiting vulnerable web-facing services like Rejetto HTTP File Server.” reads the report published by Insikt Group.

In May 2023, the Computer Emergency Response Team of Ukraine (CERT-UA) warned of a cyberespionage campaign targeting state bodies as part of an espionage campaign conducted by a threat actor tracked as UAC-0063. The attackers employed both CHERRYSPY and HATVIBE, along with the keylogger LOGPIE and STILLARCH malware.

The nation-state actor, on April 18, 2023 and April 20, 2023, sent spear-phishing emails to the department’s e-mail address, supposedly from the official mailbox of the Embassy of Tajikistan in Ukraine.

Since July 2024, TAG-110 targeted at least 62 victims across eleven countries, with notable incidents in Kazakhstan, Kyrgyzstan, and Uzbekistan.

Russia-linked APT TAG-110 uses targets Europe and Asia 1

TAG-110’s operations align with Russia’s geopolitical interests, focusing on Central Asia to maintain influence amid strained relations. The researchers pointed out that intelligence gathered in these campaigns supports Russia’s military strategies and enhances understanding of regional dynamics.

“TAG-110 is expected to continue its cyber-espionage campaigns, focusing on post-Soviet Central Asian states, Ukraine, and Ukraine’s allies. These regions are significant to Moscow due to strained relations following Russia’s invasion of Ukraine.” concludes the report. “While TAG-110’s ties to BlueDelta remain unconfirmed, its activities align with BlueDelta’s strategic interests in national security, military operations, and geopolitical influence.”

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:40 pm, Mar 16, 2025
weather icon 9°C
L: 8° | H: 11°
broken clouds
Humidity: 56 %
Pressure: 1024 mb
Wind: 12 mph NNE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 6:12 am
Sunset: 6:06 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
8° | 11°°C 0 mm 0% 11 mph 70 % 1026 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 9°°C 0 mm 0% 10 mph 89 % 1029 mb 0 mm/h
Tue Mar 18 9:00 pm
weather icon
4° | 10°°C 0 mm 0% 12 mph 78 % 1027 mb 0 mm/h
Wed Mar 19 9:00 pm
weather icon
3° | 15°°C 0 mm 0% 7 mph 79 % 1022 mb 0 mm/h
Thu Mar 20 9:00 pm
weather icon
8° | 14°°C 0 mm 0% 7 mph 78 % 1021 mb 0 mm/h
Today 3:00 pm
weather icon
9° | 10°°C 0 mm 0% 11 mph 56 % 1024 mb 0 mm/h
Today 6:00 pm
weather icon
8° | 8°°C 0 mm 0% 8 mph 58 % 1024 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 7°°C 0 mm 0% 3 mph 70 % 1026 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 5°°C 0 mm 0% 6 mph 84 % 1027 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 4°°C 0 mm 0% 7 mph 89 % 1027 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 3°°C 0 mm 0% 7 mph 81 % 1028 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0 mm 0% 7 mph 66 % 1029 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
9° | 9°°C 0 mm 0% 8 mph 52 % 1028 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€75,993.26
-1.61%
Ethereum(ETH)
€1,729.24
-2.08%
Tether(USDT)
€0.92
-0.02%
XRP(XRP)
€2.11
-5.82%
Solana(SOL)
€118.32
-4.36%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.154186
-4.30%
Shiba Inu(SHIB)
€0.000012
-0.19%
Pepe(PEPE)
€0.000006
-4.71%
Peanut the Squirrel(PNUT)
€0.189019
20.47%
Scroll to Top