TA428 conducted Operation LagTime IT, a cyber-espionage campaign targeting government organizations in East Asia and defense- and aviation-related entities in Russia and Mongolia. The intrusions used Royal Road-generated malicious RTF documents exploiting CVE-2018-0798 in Microsoft Word, including lures themed around Qasem Soleimani and COVID-19, to deliver Poison Ivy, Cotx RAT, and the malware later identified as nccTrojan or MsmRAT. Researchers said the activity was observed from at least March 2019 through 2020 and showed overlap with Chinese intrusion clusters including Tick, Tonto, and possibly DragonOK/Danti.
After initial compromise, the operators stole credentials from Outlook and lsass.exe, scanned victim networks, and moved laterally using MS17-010 tooling including EternalBlue-related exploitation. TA428 also used NBTScan, DLL side-loading with legitimate Intel and PotPlayer binaries, malicious .wll files for persistence, and follow-on malware such as Tmanger, Poison Ivy-B, and multiple nccTrojan variants. Researchers found that nccTrojan had at least two major branches: an initial-access version with standard RAT functions and XOR-obfuscated traffic, and a later-stage version installed as a Windows service that used a custom TCP protocol with AES-encrypted payloads and an activation code for command handling.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On February 18, 2021, NTT Security Japan published an analysis of nccTrojan, also called MsmRAT, linking it to TA428 attacks against defense and aviation-related organizations in Russia and Mongolia. The report identified at least four variants and described two major branches, v1 and v2.
NTT Security Japan observed nccTrojan version 1 being used in November 2020, indicating the malware branch remained active after newer variants had appeared. The report noted that v1 continued to be used even after v2 emerged.
A campaign attributed to the same actor behind Operation LagTime appears to have begun targeting Russia in July 2020, based on a backdoor C2 configuration change. The reporting linked the malware to Operation LagTime through code similarity and overlapping infrastructure, and published associated file and network indicators.
In February 2020, NTT observed a more advanced Operation LagTime IT intrusion using a COVID-19-themed RTF lure named "English_2020.02.17_13.00_MOH_daily update.doc." In this case, TA428 expanded activity to lateral movement via MS17-010 and deployed additional malware including a second Poison Ivy, Tmanger, and nccTrojan.
A TA428 phishing campaign used an RTF lure titled "How Swuleimani’s death will affect India and Pakistan.doc." created on 2020-01-06, exploiting CVE-2018-0798 to drop a Poison Ivy RAT persisted as a .wll file in Microsoft Word's STARTUP directory. The report linked the activity to TA428 through overlapping TTPs and reuse of infrastructure previously associated with the actor.
Researchers published analysis in 2020 describing Operation LagTime IT as an ongoing TA428 cyber-espionage campaign active through that year. The report documented post-compromise tooling such as Poison Ivy-B, Tmanger, credential stealers, and MS17-010-based lateral movement.
NTT Security analyzed one of two Operation LagTime IT samples observed in January 2020. This case involved the campaign's established infection chain using malicious RTF documents and follow-on malware.
Operation LagTime IT was reported by Proofpoint in July 2019, marking a public disclosure of the TA428 campaign. Later analysis cited this reporting while noting the campaign continued afterward.
NTT Security Japan identified the oldest nccTrojan sample as version 1.6 from around March 2019. The malware was linked to TA428 and assessed as part of Operation LagTime IT.
Researchers observed TA428's Operation LagTime IT campaign targeting governmental organizations in East Asia from at least around March 2019. The campaign used Royal Road-generated RTF lures exploiting CVE-2018-0798 to deploy malware including Poison Ivy and Cotx RAT.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
insight-jp.nttsecurity.com
Open sourcesebdraven.medium.com
Open sourcelab52.io
Open sourceproofpoint.com
Open sourcevblocalhost.com
Open sourcevblocalhost.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.