TAG-100 Uses Open-Source Tools in Suspected Global Espionage Campaign, Compromising Two Asia-Pacific Intergovernmental Bodies
ID: 701997fb-241b-579c-8e89-a2d1e1b0b5d7
STIX ID: report--701997fb-241b-579c-8e89-a2d1e1b0b5d7
Feed Name: Recorded Future Blog
Recorded Future’s Insikt Group attributes a suspected cyber-espionage campaign to TAG-100 that exploited vulnerable internet-facing devices and deployed open-source Go backdoors (Pantegana, SparkRAT) to target government, diplomatic, trade, and private-sector organizations across at least ten countries, including two Asia-Pacific intergovernmental organizations. The report highlights exploitation attempts against appliances and services such as Citrix NetScaler, F5 BIG-IP, Microsoft Exchange, Palo Alto GlobalProtect (CVE-2024-3400), and others, and recommends patching, enhanced monitoring, network segmentation, multi-factor authentication, and use of threat intelligence to detect and block associated infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
