Targets Tajikistan: New Macro Word Documents Phishing Tactics
May 23, 2025, 1:08 p.m.
Description
From January to February 2025, a phishing campaign targeting Tajikistan was detected and attributed to TAG-110, a Russia-aligned threat actor. The campaign used Tajikistan government-themed documents as lures, shifting from previous tactics to macro-enabled Word template files for initial payload delivery. This change in approach demonstrates TAG-110's evolving tactics. The group's persistent targeting of Tajik government, educational, and research institutions aligns with Russia's strategy to maintain influence in Central Asia. The campaign likely aims to gather intelligence for influencing regional politics or security, particularly during sensitive events like elections or geopolitical tensions.
Tags
Date
- Created: May 22, 2025, 9:54 p.m.
- Published: May 22, 2025, 9:54 p.m.
- Modified: May 23, 2025, 1:08 p.m.
Indicators
- d60e54854f2b28c2ce197f8a3b37440dfa8dea18ce7939a356f5503ece9e5eb7
- 8508003c5aafdf89749d0abbfb9f5deb6d7b615f604bbb11b8702ddba2e365e7
- 6ac6a0dd78d2e3f58e95fa1a20b3ab22b4b49a1ab816dcfb32fd6864e1969ac3
- 6c81d2af950e958f4872d3ced470d9f70b7d73bc0b92c20a34ce8bf75d551609
- 38.180.206.61
- 188.130.234.189
Additional Informations
- Defense
- Education
- Government
- Tajikistan