China-Nexus TAG-112 Compromises Tibetan Websites to Distribute Cobalt Strike
ID: df7a07ec-50a4-5055-8f3e-096c99cd88dd
STIX ID: report--df7a07ec-50a4-5055-8f3e-096c99cd88dd
Feed Name: Recorded Future Blog
Recorded Future’s Insikt Group observed a China-linked threat actor labeled TAG-112 compromise of Tibetan websites (tibetpost.net and gyudmedtantricuniversity.org) in mid-2024 by exploiting Joomla vulnerabilities to inject malicious JavaScript that spoofed a TLS certificate error and pushed Cobalt Strike payloads; the report includes C2 domains and IPs, multiple Cobalt Strike beacon hashes, loader hashes, certificates, and MITRE ATT&CK mappings, and recommends IDS/IPS tuning, user training, Cobalt Strike detection, and network monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
