logo

Russia-Aligned TAG-110 Targets Asia and Europe with HATVIBE and CHERRYSPY

ID: 75f912c7-2ba8-577a-b54d-0ea282013aca

STIX ID: report--75f912c7-2ba8-577a-b54d-0ea282013aca

Feed Name: Recorded Future Blog

Threat Score
85/100

Date Published: 2024-11-21

Date Updated: 2026-04-28

...
...

Insikt Group reports an ongoing Russia-aligned cyber-espionage campaign by TAG-110 (linked to BlueDelta/APT28) targeting governments, human-rights organizations, and educational institutions across Central Asia, East Asia, and Europe using custom malware HATVIBE (an mshta-executed loader) and CHERRYSPY (a Python backdoor). The analysis includes 62 identified victims since July 2024, lists C2 domains and IPs, maps techniques to MITRE ATT&CK, notes exploitation vectors (phishing and public-facing application vulnerabilities), and provides IoCs and detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.