logo

China-Nexus TAG-112 Compromises Tibetan Websites to Distribute Cobalt Strike

ID: df7a07ec-50a4-5055-8f3e-096c99cd88dd

STIX ID: report--df7a07ec-50a4-5055-8f3e-096c99cd88dd

Feed Name: Recorded Future Blog

Threat Score
75/100

Date Published: 2024-11-12

Date Updated: 2026-04-28

...
...

Recorded Future’s Insikt Group observed a China-linked threat actor labeled TAG-112 compromise of Tibetan websites (tibetpost.net and gyudmedtantricuniversity.org) in mid-2024 by exploiting Joomla vulnerabilities to inject malicious JavaScript that spoofed a TLS certificate error and pushed Cobalt Strike payloads; the report includes C2 domains and IPs, multiple Cobalt Strike beacon hashes, loader hashes, certificates, and MITRE ATT&CK mappings, and recommends IDS/IPS tuning, user training, Cobalt Strike detection, and network monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.