logo

Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage Campaign

ID: b1b2c8cd-4dd8-5b59-8ba5-f2560bf30ffd

STIX ID: report--b1b2c8cd-4dd8-5b59-8ba5-f2560bf30ffd

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2024-02-16

Date Updated: 2026-04-28

...
...

Recorded Future’s Insikt Group attributes a cross-site scripting-based campaign against Roundcube webmail to TAG-70 (likely Belarus/Russia-aligned), describing active exploitation between October–December 2023 (and related activity since 2020) that targeted 80+ government, military, and infrastructure organizations in Georgia, Poland, Ukraine and elsewhere; the attackers used JavaScript loaders delivered via XSS to capture credentials and relay data to C2 infrastructure (often via Tor), and the report provides malware samples, domains, IPs, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.