TAG-28 is a Chinese state-sponsored threat actor that has been targeting Indian organizations, including media conglomerates and government agencies. They have been using the Winnti malware, which is commonly shared among Chinese state-sponsored groups. TAG-28's main objective is to gather intelligence on Indian targets, potentially for espionage purposes.
Executive Summary
TAG-28 is identified as a Chinese state-sponsored threat actor targeting Indian organizations, including media conglomerates and government agencies. Their primary objective appears to be intelligence gathering for espionage purposes. TAG-28 has been linked to the use of Winnti malware, commonly associated with other Chinese state-sponsored groups.
Goals & Targeting
TAG-28's primary motivation is intelligence gathering, likely for strategic or political purposes. Their targeting of Indian media and government agencies indicates a focus on collecting sensitive information related to national security, policy-making, and public perception in India. The group appears to prioritize sectors that could yield valuable insights into India's internal affairs and diplomatic communications.
Enhanced Description
TAG-28 is a state-sponsored cyber threat actor attributed to China, who has demonstrated a focus on targeting Indian organizations. The group primarily aims to gather sensitive information through espionage activities. TAG-28's operations include the use of Winnti malware, which is known for its modular capabilities and long-term persistence in compromised systems. This malware enables TAG-28 to maintain a presence within targeted networks while collecting data and exfiltrating it to external servers. The group's targeting of media conglomerates and government agencies suggests an interest in political and strategic information related to India. Despite sharing malware with other Chinese state-sponsored actors, TAG-28 appears to have maintained a lower profile, making its campaign patterns less well-documented compared to more active groups.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TAG-28's campaigns focus on long-term access and data collection from Indian targets. The group's operational tempo is not well-documented, but their use of Winnti malware suggests a focus on stealth and persistence. Limited publicly available information on TAG-28 implies either a niche targeting approach or low activity levels compared to other Chinese state-sponsored groups. Notable past operations include targeted intrusions into Indian media and government networks, likely in alignment with broader geopolitical interests.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in TAG-28's identification as a Chinese state-sponsored actor is moderate due to shared TTPs with other known groups. However, the limited availability of detailed campaign data and specific attack patterns introduces uncertainty about their exact capabilities, targeting scope, and operational frequency.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics