logo

Double-Tap Campaign: Russia-nexus APT possibly related to APT28 conducts cyber espionage on Central Asia and Kazakhstan diplomatic relations

ID: a255f376-6b04-5611-9d14-a7deb9da4ad5

STIX ID: report--a255f376-6b04-5611-9d14-a7deb9da4ad5

Feed Name: Sekoia.io Blog

Threat Score
85/100

Date Published: 2025-01-13

Date Updated: 2026-04-29

Author: Amaury G., Maxime A., Erwan Chevalier, Felix Aimé and Sekoia TDR

...
...

Sekoia documents an ongoing, nation-state-aligned cyber-espionage campaign (UAC-0063) that weaponized legitimate Kazakhstan Ministry of Foreign Affairs Word documents to deploy a unique "Double-Tap" macro chain which drops an HTA-based VBS backdoor (HATVIBE) and ultimately CHERRYSPY; the report includes technical analysis, YARA rules, IOCs (domains, IPs, document hashes), Sigma detections, and assesses medium-confidence overlap with APT28/GRU while highlighting strategic targeting of Kazakhstan and Central Asia for diplomatic and economic intelligence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.