216.73.217.22

Targets Tajikistan: New Macro Word Documents Phishing Tactics

· Published 22/05/2025 21:54 · Modified 23/05/2025 13:08

Export JSON

Essential information

Published
22/05/2025 21:54
Modified
23/05/2025 13:08
Tags
2025-05-22 cherryspy espionage government hatvibe logpie phishing pyplunderplug russia-aligned tajikistan
Related entities
6 observables, 1 intrusion sets (apt), 3 techniques (mitre), 4 malware, 4 others

Description

From January to February 2025, a campaign targeting was detected and attributed to TAG-110, a threat actor. The campaign used -themed documents as lures, shifting from previous tactics to macro-enabled Word template files for initial payload delivery. This change in approach demonstrates TAG-110's evolving tactics. The group's persistent targeting of Tajik , educational, and research institutions aligns with Russia's strategy to maintain influence in Central Asia. The campaign likely aims to gather intelligence for influencing regional politics or security, particularly during sensitive events like elections or geopolitical tensions.

External references