TAG-110, also tracked as UAC-0063, is a Russia-aligned cyber-espionage threat actor active since at least 2021. The group has been associated with sustained intelligence-collection operations against government, diplomatic, educational, and research organizations, with a strong concentration on Central Asia and Ukraine and additional activity affecting European diplomatic targets. CERT-UA has assessed with medium confidence that UAC-0063 overlaps with APT28, also known as BlueDelta or Fancy Bear, a threat cluster linked to Russia’s GRU, although public technical reporting has also noted that the evidence is not yet sufficient to conclusively confirm that relationship. TAG-110 is known for spear-phishing campaigns that weaponize legitimate or legitimate-looking government documents, including documents stolen from previously compromised victims, to infect new targets. The actor has used malicious Microsoft Word documents and macro-enabled Word templates to establish initial access and persistence. Earlier activity commonly delivered the HTA-based loader HATVIBE through VBA macros, while later campaigns in Tajikistan used macro-enabled template files that copied themselves into the Microsoft Word startup folder for automatic execution and command-and-control. Reporting also links the group to exploitation of CVE-2024-23692 in HFS HTTP File Server, indicating use of both phishing and public-facing application exploitation. The actor’s malware ecosystem includes HATVIBE, CHERRYSPY (also known as DownExPyer), DownEx, LOGPIE, STILLARCH, and PyPlunderPlug. HATVIBE functions as a loader and backdoor that establishes persistence and retrieves follow-on payloads. CHERRYSPY supports remote tasking including file theft, command execution, screenshot capture, and task management. PyPlunderPlug has been used to collect files from removable media for later exfiltration. LOGPIE-related activity and tasking indicate keylogging and retrieval of captured keystroke data. Across observed intrusions, TAG-110 has maintained persistence with scheduled tasks, used compromised email accounts to resend malicious lures from trusted correspondents, and deployed Python-based tooling after initial compromise. Victimology includes Ukrainian scientific and research institutions, Tajik government, educational, and research entities, government organizations in Kazakhstan and Afghanistan, and diplomatic missions or embassies in Germany, the United Kingdom, the Netherlands, Romania, Georgia, Kazakhstan, and Afghanistan. The group’s targeting and tradecraft are consistent with strategic espionage and intelligence-gathering objectives aligned with Russian geopolitical interests in Central Asia, Ukraine, and related diplomatic environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Threat Actors (TAs) leveraging a Remote Code Execution (RCE) vulnerability, identified as CVE-2023-38831, to deliver their payload on compromised systems... The aforementioned vulnerability allows the WinRAR application to extract and execute the malicious script when a user tries to open a benign file within the archive.
Слід додати, що в червні 2024 року зафіксовано численні випадки встановлення бекдору HATVIBE шляхом експлуатації вразливості (вірогідно, CVE-2024-23692) в програмному продукті HFS HTTP File Server
85 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a separate Russia-linked cyber-espionage operation previously documented by Bitdefender as expanding from Central Asia into Europe.
Espionage-focused activity expanding to European embassies; uses stolen legitimate documents for follow-on targeting and delivers HATVIBE malware; also assessed in reporting as Russia-linked and potentially overlapping with APT28.
Russia-aligned actor conducting spear-phishing against Tajikistan using weaponized Word documents; shifted from prior HTA loader (HATVIBE) to macro-enabled Word templates.
Cyber espionage activity cluster targeting government, educational, research, embassy, and other public sector organizations in Central Asia, East Asia, Europe, and specifically Tajikistan, using spear-phishing and malware delivery via macro-enabled Word templates and previously HTA-based loaders.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.