TAG-28 is a China-linked suspected state-sponsored intrusion cluster associated with cyber espionage operations targeting Indian organizations. Reported victims include Bennett Coleman and Co. Ltd. (The Times Group), the Unique Identification Authority of India (UIDAI), and the Madhya Pradesh Police. The group has been associated with use of Winnti malware in operations against media targets. The actor’s targeting indicates an intelligence-collection mission focused on obtaining sensitive government and personal data as well as insight into media reporting. Intrusions against UIDAI are consistent with efforts to access large-scale personally identifiable and biometric data holdings that could support identification of high-value individuals, social-engineering operations, and enrichment of other intelligence datasets. Targeting of The Times Group is consistent with surveillance of journalists, their sources, and potentially sensitive pre-publication reporting related to China and its leadership. Available reporting indicates espionage rather than disruptive manipulation of publishing systems. TAG-28 fits within the broader pattern of Chinese cyber operations directed at Indian strategic interests. Based on the available facts, the group is best characterized as a China-linked espionage actor using malware-enabled intrusion activity against government, law-enforcement, and media entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.