TAG-70 is a Russia-based cyber espionage threat group associated with campaigns targeting webmail platforms used by government, military, diplomatic, and national infrastructure-related organizations. The group has been linked to exploitation of Roundcube and Zimbra vulnerabilities to gain access to victims’ email environments, with activity observed in the context of the Russia–Ukraine war. Reporting has assessed overlap between TAG-70 and clusters tracked as Winter Vivern, TA473, and UAC-0114. TAG-70 has been observed exploiting Roundcube, including CVE-2023-5631, in campaigns active since at least October 2023. These operations targeted more than 80 organizations, primarily in Georgia, Poland, and Ukraine. The exploitation enabled access to mailbox contents, including listing and exfiltration of emails, with minimal user interaction beyond opening a malicious message. The group was also previously linked to exploitation of Zimbra via CVE-2022-27926 in March 2023 against European military, government, and diplomatic organizations. The actor has used spoofing in support of initial access, including creation of a fake website impersonating the Ministry of Foreign Affairs of Ukraine to lure victims into downloading malicious software. Operationally, TAG-70 has been reported to use command-and-control infrastructure administered through Tor, reflecting an emphasis on defense evasion and post-compromise control. Its activity profile is consistent with credential and mailbox-focused intrusion operations aimed at intelligence collection rather than disruptive or financially motivated attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
"In March 2023, TAG-70 was attributed to the exploitation of the Zimbra webmail portal via CVE-2022-27926..."
"TAG-70 has been discovered to be exploiting Roundcube webmail servers with a recently disclosed Cross-Site Scripting vulnerability CVE-2023-5631."
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a group previously observed abusing Roundcube vulnerabilities; not attributed to the current exploitation attempt described.
Cyber-espionage activity focused on compromising webmail (Roundcube, previously Zimbra) to access and exfiltrate mailbox contents from government/military/diplomatic and national infrastructure-related targets, supporting intelligence collection related to the Russia–Ukraine war.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.