Targets Tajikistan: New Macro Word Documents Phishing Tactics

May 23, 2025, 1:08 p.m.

Description

From January to February 2025, a phishing campaign targeting Tajikistan was detected and attributed to TAG-110, a Russia-aligned threat actor. The campaign used Tajikistan government-themed documents as lures, shifting from previous tactics to macro-enabled Word template files for initial payload delivery. This change in approach demonstrates TAG-110's evolving tactics. The group's persistent targeting of Tajik government, educational, and research institutions aligns with Russia's strategy to maintain influence in Central Asia. The campaign likely aims to gather intelligence for influencing regional politics or security, particularly during sensitive events like elections or geopolitical tensions.

Date

  • Created: May 22, 2025, 9:54 p.m.
  • Published: May 22, 2025, 9:54 p.m.
  • Modified: May 23, 2025, 1:08 p.m.

Indicators

  • d60e54854f2b28c2ce197f8a3b37440dfa8dea18ce7939a356f5503ece9e5eb7
  • 8508003c5aafdf89749d0abbfb9f5deb6d7b615f604bbb11b8702ddba2e365e7
  • 6ac6a0dd78d2e3f58e95fa1a20b3ab22b4b49a1ab816dcfb32fd6864e1969ac3
  • 6c81d2af950e958f4872d3ced470d9f70b7d73bc0b92c20a34ce8bf75d551609
  • 38.180.206.61
  • 188.130.234.189

Attack Patterns

  • PyPlunderPlug
  • LOGPIE
  • CHERRYSPY
  • HATVIBE
  • TAG-110

Additional Informations

  • Defense
  • Education
  • Government
  • Tajikistan