Russia-Aligned TAG-110 Targets Asia and Europe with HATVIBE and CHERRYSPY
ID: 75f912c7-2ba8-577a-b54d-0ea282013aca
STIX ID: report--75f912c7-2ba8-577a-b54d-0ea282013aca
Feed Name: Recorded Future Blog
Insikt Group reports an ongoing Russia-aligned cyber-espionage campaign by TAG-110 (linked to BlueDelta/APT28) targeting governments, human-rights organizations, and educational institutions across Central Asia, East Asia, and Europe using custom malware HATVIBE (an mshta-executed loader) and CHERRYSPY (a Python backdoor). The analysis includes 62 identified victims since July 2024, lists C2 domains and IPs, maps techniques to MITRE ATT&CK, notes exploitation vectors (phishing and public-facing application vulnerabilities), and provides IoCs and detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
