#TAG110
A new TAG-110 report, including victimology and recent C2 infrastructure, has just landed. #TAG110 #BlueDelta #APT28 www.recordedfuture.com/research/rus...
Russia-Aligned TAG-110 Targets Asia and Europe with HATVIBE and CHERRYSPY
TAG-110, a Russia-aligned threat group, targets organizations across Asia and Europe using HATVIBE and CHERRYSPY malware for espionage. Learn how Recorded Future's analysis uncovers the group’s tactic...
www.recordedfuture.com
November 21, 2024 at 3:38 PM
Russia-linked hackers, TAG-110, target Tajikistan's government with weaponized Word documents in a sophisticated cyber espionage campaign. #CyberSecurity #Tajikistan #APT28 #TAG110 thedailytechfeed.com/russia-linke...
May 27, 2025 at 5:29 PM
Great work by Sekoia uncovering new #BlueDelta #APT28 #Sofacy #FancyBear #ForestBlizzard #TAG110 malware samples. Linked to CERT-UA’s BeardShell & Covenant frameworks + revealed fresh weaponized docs & subtle TTPs. Activity ties to Russia-nexus ops incl. Double-Tap. blog.sekoia.io/apt28-operat...
APT28 Operation Phantom Net Voxel
APT28 Operation Phantom Net Voxel: weaponized Office lures, COM-hijack DLL, PNG stego to Covenant Grunt via Koofr, BeardShell on icedrive.
blog.sekoia.io
September 16, 2025 at 9:24 AM
Fun fact: We have a rule for HATVIBE (TAG110, aka TA426, aka Zebrocy) in our ETPRO ruleset. I'll be moving a rule for Snort and Suricata nearly identical to the rule in the report to ETOPEN today. Look forward to that in today's rule release.

Also, coverage for the C2 Domains under "TA426/Zebrocy"
November 21, 2024 at 6:52 PM