Russian Threat Actor TAG-110 Goes Phishing in Tajikistan
ID: a592b37e-f3c6-5a41-a78f-c15f82b80635
STIX ID: report--a592b37e-f3c6-5a41-a78f-c15f82b80635
Feed Name: Dark Reading
Date Published: 2025-05-22
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
Recorded Future's Insikt Group and other analysts attribute espionage campaigns in Tajikistan and Central Asia to TAG-110, a Russia-aligned APT that used spear-phishing with trojanized macro-enabled Word/.dotm documents (and previously HTA HATVIBE) to establish persistence via global Word templates and deliver malware families including CHERRYSPY, LOGPIE, and PyPlunderPlug; the report includes IoCs and recommends disabling macros and monitoring Word startup templates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
