Rusia-Aligned TAG-110 Targets Asia and Europe with HATVIBE and CHERRYSPY
ID: fa6bf074-8995-42da-ae13-18c6d1c24c77
STIX ID: report--fa6bf074-8995-42da-ae13-18c6d1c24c77
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2024-11-20
Last Modified Date: 2024-11-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group reports an active Russia-aligned cyber-espionage campaign (TAG-110/UAC-0063) targeting governments, human rights, education, and related organizations—primarily in Central Asia—using the HATVIBE HTA/VBScript loader and the CHERRYSPY Python backdoor; the report documents 62 victims since July 2024, C2 infrastructure and domains, attack patterns (including exploitation of a Rejetto HFS vulnerability and phishing), detection rules (Snort/Suricata/YARA), and recommended mitigations.
