logo

Rusia-Aligned TAG-110 Targets Asia and Europe with HATVIBE and CHERRYSPY

ID: fa6bf074-8995-42da-ae13-18c6d1c24c77

STIX ID: report--fa6bf074-8995-42da-ae13-18c6d1c24c77

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2024-11-20

Last Modified Date: 2024-11-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group reports an active Russia-aligned cyber-espionage campaign (TAG-110/UAC-0063) targeting governments, human rights, education, and related organizations—primarily in Central Asia—using the HATVIBE HTA/VBScript loader and the CHERRYSPY Python backdoor; the report documents 62 victims since July 2024, C2 infrastructure and domains, attack patterns (including exploitation of a Rejetto HFS vulnerability and phishing), detection rules (Snort/Suricata/YARA), and recommended mitigations.