Full Report
Russia-aligned TAG-110 shifts to .dotm phishing lures in a 2025 campaign against Tajikistan’s public sector, advancing cyber-espionage in Central Asia.
Analysis Summary
# Threat Actor: TAG-110
## Attribution & Identity
* **Attribution:** Russia-aligned threat actor.
* **Aliases/Overlap:** Overlaps with UAC-0063. Medium confidence association with APT28 (BlueDelta) cited by CERT-UA.
* **Historical Activity:** Active since at least 2021, conducting cyber-espionage campaigns primarily targeting Central Asia.
## Activity Summary
During January to February 2025, Insikt Group detected a phishing campaign specifically targeting entities in **Tajikistan**. The campaign utilized **Tajikistan government-themed documents** as lure material. This recent activity shows an evolution in tactics, as the actor shifted from using embedded HTA (HATVIBE) payloads to leveraging **macro-enabled Word template files (.dotm files)** for delivering the initial payload. This is consistent with TAG-110's historical focus on intelligence gathering to support Russia's post-Soviet sphere of influence policy in Central Asia.
## Tactics, Techniques & Procedures
- Spearphishing via document attachments (evolution from HTA-embedded lures to `.dotm` files).
- Initial access achieved via macro execution in Word documents.
- Persistence mechanism evolution: Recent deployment involves placing the malicious file in the **Microsoft Word STARTUP folder** for automatic execution, replacing the previous use of the HATVIBE payload to create a scheduled task.
- Reused VBA code from previous campaigns was noted, aiding attribution.
- Modification of registry keys related to Word security (AccessVBOM under `HKEY_CURRENT_USER\Software\Microsoft\Office\Word\Security`) is suspected to enable or manipulate VBA macro behavior.
## Targeting
* **Sectors:** Government, educational, and research institutions; public sector entities; academic and research bodies; diplomatic missions.
* **Geography:** Primarily Central Asia, with the recent campaign explicitly targeting **Tajikistan**. Historical targeting includes Kazakhstan and Uzbekistan.
* **Victims:** Public sector entities, entities involved in upcoming elections, military operations, or geopolitical events that the Kremlin may seek to influence.
## Tools & Infrastructure
* **Malware families used (Historically/Expected):** HATVIBE (HTA-based malware for initial access/persistence), CHERRYSPY (DownExPyer), LOGPIE, and PyPlunderPlug.
* **Infrastructure (C2):** One identified IP address shared by the recent malicious documents: `38.180.206[.]61`. This IP was previously identified as a HATVIBE C2 server attributed to TAG-110.
## Implications
TAG-110's persistent targeting of Central Asian government and academic bodies directly supports Russian intelligence-gathering objectives intended to bolster regional political and security influence, particularly around sensitive national events like elections. The shift in malware deployment from scheduled tasks (using HATVIBE) to leveraging the Word STARTUP folder indicates an evolution towards a potentially cleaner or faster persistence mechanism.
## Mitigations
- Monitor for and alert on the creation or modification of global template files (.dotm) within the **Microsoft Word startup folder**.
- Detect and investigate registry modifications to the **AccessVBOM** key under `HKEY_CURRENT_USER\Software\Microsoft\Office\Word\Security`.
- Disable Microsoft Office macros by default and enforce Group Policy Objects (GPOs) to prevent user enabling, unless explicitly approved.
- Monitor for infrastructure associated with TAG-110, such as the C2 IP `38.180.206[.]61`.