logo

Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage Campaign

ID: f12a0f3b-37fb-40c0-b2e7-cb4dccd05d04

STIX ID: report--f12a0f3b-37fb-40c0-b2e7-cb4dccd05d04

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2024-02-15

Last Modified Date: 2024-02-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group reports that TAG-70, a Russia/Belarus-aligned threat actor, conducted an October 2023 campaign exploiting a Roundcube XSS (CVE-2023-5631) to deploy JavaScript loaders that capture credentials and exfiltrate email from government and military webmail servers across Ukraine, Georgia, Poland and other countries; the report includes malware payloads, hosting and C2 infrastructure, IoCs (domains, IPs, SHA256s), ATT&CK mappings, and recommended mitigations.