logo

Double-Tap: APT28-Linked Espionage on Kazakhstan

ID: 41ec3f37-d437-5ef4-8425-d5794129eb5f

STIX ID: report--41ec3f37-d437-5ef4-8425-d5794129eb5f

Feed Name: Sekoia.com

Threat Score
85/100

Date Published: 2025-01-13

Date Updated: 2026-07-20

...
...

This Sekoia report documents an ongoing cyber-espionage campaign (UAC-0063) that weaponized legitimate Kazakhstan Ministry of Foreign Affairs Word documents to deploy a Double-Tap macro chain that installs a VBS backdoor (HATVIBE) and likely a Python backdoor (CHERRYSPY); it includes technical analysis of the infection chain, YARA rules, IOCs (hashes and C2s), detection guidance, and an assessment of medium-confidence links to APT28/GRU and strategic targeting of Central Asian diplomatic and economic intelligence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.