Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage Campaign
ID: b1b2c8cd-4dd8-5b59-8ba5-f2560bf30ffd
STIX ID: report--b1b2c8cd-4dd8-5b59-8ba5-f2560bf30ffd
Feed Name: Recorded Future Blog
Recorded Future’s Insikt Group attributes a cross-site scripting-based campaign against Roundcube webmail to TAG-70 (likely Belarus/Russia-aligned), describing active exploitation between October–December 2023 (and related activity since 2020) that targeted 80+ government, military, and infrastructure organizations in Georgia, Poland, Ukraine and elsewhere; the attackers used JavaScript loaders delivered via XSS to capture credentials and relay data to C2 infrastructure (often via Tor), and the report provides malware samples, domains, IPs, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
