Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Russia -related hackers are oriented
Global Security

Russia -related hackers are oriented

AdminBy AdminMay 27, 2025No Comments3 Mins Read
Weaponized Word Documents
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


May 27 2025Red LakshmananCriminal software / intelligence threats

Armed documents

The actor aligned in Russia, known as the Tag-110, conducted a fashion company aimed at Tajikistan using macro-shaped words as the initial useful load.

The attack network is a departure from previously documented HTML -application (.hta), dubbed Hatvibe, recorded Hatvibe Hatvibe, recorded in the analysis “Insikt Group Future”.

“Given the historical orientation to the public sector organization in Central Asia, this company is likely noted.

“These cyber operations are probably aimed at gathering exploration to influence regional policy and security, especially during sensitive events, such as choices or geopolitical tensions.”

Cybersecurity

Tag -10, also called UAC-0063, is the name designed for A group of activity threatening it know for him bearings European embassies, as well as other organizations of Central Asia, East Asia and Europe. It is believed that it has been actively operating at least 2021.

Estimated to share overlappings with Russian national cracking crew APT28, activity related to the actor threats First documented In May 2023, the Romanian Cybersecurity Company Bitdefender Due to the Company, which delivered malicious software, codan of the said Downex (AKA Stilarch) aimed at government agencies in Kazakhstan and Afghanistan.

However, in the same month after her officially appointed a team of emergencies in emergencies (CERT-UA) disclosed Cyberattacks aimed at government agencies in the country using malware such as Logpie, CherrySpy (aka DownExpyer), Downex and PypLunderPlug.

The latest company aimed at Tajikistan’s organization, which has been observed since January 2025, demonstrates a deviation from Hatvibe, distributed by HTA, extended attachments, in favor of macro-shaped words (.dotm) files, revealing the evolution of their tactics.

“Previously, Tag -10 used macro-documents with words support to deliver Hatvibe, malicious HTA software for initial access,” the future recorded. “Recently identified documents do not contain built -in HTA HATVIBE load to create a planned task and instead use a global template file placed in the” Running “folder for sustainability.

Cybersecurity

It has been found that phishing emails use documents with the subject matter of Tajikistan as a bait material that corresponds to its historical use of the government’s legal documents as a vector of malware. However, the cybersecurity campaign said it could not independently check the authenticity of these documents.

Posted with Macros VBA files, which is responsible for placing the document template in the Microsoft Word launch folder for automatic execution and further initiation with the team server and control (C2) and potentially performs an additional VBA code that comes with C2 answers. The exact nature of the useful loads in the second stage is unknown.

“However, based on the historical activity and set of Tag -10 tools, it is likely that successful initial access through macro support templates will deploy additional malware, such as Hatvibe, CherrySpy, LogPie or potentially new, designed by customs load for emergency operations.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025

Popular Chrome Extensions API leaks, user data via HTTP and Hard Codes

June 5, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025

Popular Chrome Extensions API leaks, user data via HTTP and Hard Codes

June 5, 2025

Researchers in detail in detail decisively developing tactics as it expands its geographical volume

June 5, 2025

Iran related

June 5, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.