Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TAG-28

Description

TAG-28 is a Chinese state-sponsored threat actor that has been targeting Indian organizations, including media conglomerates and government agencies. They have been using the Winnti malware, which is commonly shared among Chinese state-sponsored groups. TAG-28's main objective is to gather intelligence on Indian targets, potentially for espionage purposes.

AI Analysis

· 1 week ago

Executive Summary

TAG-28 is identified as a Chinese state-sponsored threat actor targeting Indian organizations, including media conglomerates and government agencies. Their primary objective appears to be intelligence gathering for espionage purposes. TAG-28 has been linked to the use of Winnti malware, commonly associated with other Chinese state-sponsored groups.

Goals & Targeting

TAG-28's primary motivation is intelligence gathering, likely for strategic or political purposes. Their targeting of Indian media and government agencies indicates a focus on collecting sensitive information related to national security, policy-making, and public perception in India. The group appears to prioritize sectors that could yield valuable insights into India's internal affairs and diplomatic communications.

Enhanced Description

TAG-28 is a state-sponsored cyber threat actor attributed to China, who has demonstrated a focus on targeting Indian organizations. The group primarily aims to gather sensitive information through espionage activities. TAG-28's operations include the use of Winnti malware, which is known for its modular capabilities and long-term persistence in compromised systems. This malware enables TAG-28 to maintain a presence within targeted networks while collecting data and exfiltrating it to external servers. The group's targeting of media conglomerates and government agencies suggests an interest in political and strategic information related to India. Despite sharing malware with other Chinese state-sponsored actors, TAG-28 appears to have maintained a lower profile, making its campaign patterns less well-documented compared to more active groups.

Key Capabilities

  • Network intrusion capabilities
  • Data exfiltration techniques
  • Persistent access through malware
  • Cyber espionage activities

MITRE ATT&CK Tactics

Reconnaissance
Collection

ATT&CK Techniques

T1566.001
T1030
T1074.004
T1055
T1003
T1005

Software / Tooling

Winnti malware
Mimikatz
Process hollowing
Custom C2 frameworks
Cobalt Strike-like campaign tools

Campaigns & Victims

TAG-28's campaigns focus on long-term access and data collection from Indian targets. The group's operational tempo is not well-documented, but their use of Winnti malware suggests a focus on stealth and persistence. Limited publicly available information on TAG-28 implies either a niche targeting approach or low activity levels compared to other Chinese state-sponsored groups. Notable past operations include targeted intrusions into Indian media and government networks, likely in alignment with broader geopolitical interests.

IOC Patterns

  • Spear-phishing campaigns with malicious Office document attachments
  • Use of LNK files for persistence
  • Encrypted C2 communications
  • Fileless malware techniques
  • Scheduled task creation for persistence

Recommended Actions

  • Implement network monitoring for unusual east-west traffic patterns.
  • Conduct regular phishing simulations to improve employee awareness.
  • Deploy endpoint detection and response (EDR) solutions to detect process hollowing and fileless malware activities.
  • Monitor for signs of credential theft, such as unexpected LSASS processes or rundll32.exe executions.
  • Block execution of scripts from untrusted sources.

Suggested Tags

State-sponsored
Espionage
South Asia
Media sector
Government agencies

Confidence Assessment

The confidence in TAG-28's identification as a Chinese state-sponsored actor is moderate due to shared TTPs with other known groups. However, the limited availability of detailed campaign data and specific attack patterns introduces uncertainty about their exact capabilities, targeting scope, and operational frequency.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Government Targeting
State-sponsored
Espionage
South Asia
Media sector
Government agencies

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.