Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TAG-112

Also known as: tag propagation, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Chanitor, Agrius, Threat Intelligence, Chimaera, APT34, the SVR

Description

TAG‑112 primarily conducts campaigns against Tibetan organizations by leveraging well‑known weaknesses in Joomla installations. Once an attacker compromises a site, they inject malicious JavaScript that displays a spoofed TLS certificate error. This trick forces users to download a fake security certificate which then installs a Cobalt Strike beacon for remote control. In addition to web delivery, the actor uses Cloudflare for infrastructure obfuscation and employs ad‑versary‑in‑the‑middle tactics on captive portals to redirect DNS and HTTP flows through controlled domains. Their malware bundles include self‑deleting components that erase file and command histories, clear registry entries, and remove network share connections—exemplifying a layered defense‑evasion approach. TAG‑112’s toolkit also contains backdoors such as Backdoor.Oldrea, Heyoka Backdoor, and White Company, which provide persistence and facilitate credential harvesting, especially from web browsers. The presence of AI‑augmented operational support suggests an evolving threat capability aimed at streamlining both attack vectors and post‑exploitation stages. While the group’s financial motives are noted in its description, most evidence points toward espionage objectives—gaining political intelligence on Tibetan communities—while maintaining a low‑profile footprint that complicates attribution.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Energy
Transportation
Education
Critical infrastructure
Healthcare
Media
Maritime
Hospitality
Telecommunications
Gaming
Non profit
Information technology
Entertainment
Utilities
Aerospace
Think tank
Aviation
Retail

Targeted Countries / Regions

CN
UA
US
RU
TW
KR
IR
AZ
JP
CA
IN
PK
BY

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 2 days ago

Executive Summary

TAG‑112 is a Chinese state‑sponsored Advanced Persistent Threat that has exploited Joomla CMS vulnerabilities on Tibetan community websites to drop Cobalt Strike and steal data while evading detection. The group blends low‑tech social engineering techniques—such as spoofed TLS certificate prompts—with more sophisticated traffic manipulation on captive portals and phishing of Microsoft Entra ID device registration flows. Its operations demonstrate a mix of espionage and opportunistic financial motives, targeting both governmental and civilian entities.

Goals & Targeting

The strategic objective of TAG‑112 is dual: acquire politically relevant information from Tibetan community organizations and exploit any discovered vulnerabilities for further infiltration. By targeting sites with CMS weaknesses, the actor ensures continuous footholds in critical regions while simultaneously using advanced ransomware‑style tactics when financially motivated. Their global reach—spanning China, Ukraine, Russia, Iran, and the U.S.—indicates a broadening threat envelope beyond Tibetan entities. Their targeting profile prefers publicly accessible web properties to initiate attacks but also extends to corporate Microsoft environments through phishing of OAuth/device code flows. Such diversification serves both espionage of sensitive data and opportunistic financial gains via potential ransomware or data exfiltration, reflecting a flexible operational paradigm.

Enhanced Description

Key Capabilities

  • Compromising websites via CMS vulnerabilities
  • Exploiting Joomla content management system weaknesses
  • Embedding malicious JavaScript into web pages
  • Spoofing TLS certificate error prompts to trick users
  • Delivering Cobalt Strike remote‑access trojan
  • Using Cloudflare for infrastructure concealment
  • Removing system traces (self‑deletion, file/folder deletion)
  • Traffic manipulation via DNS and HTTP redirect from captive portals
  • Adversary-in-the-Middle phishing using doppelganger domains mimicking Microsoft services
  • Device code and OAuth code phishing to register devices in Microsoft Entra ID
  • Malware delivery to Windows systems and Android APKs
  • AI‑augmented operation support

MITRE ATT&CK Tactics

Initial Access
Execution
Command & Control
Defense Evasion
Impact
Credential Access
Collection

ATT&CK Techniques

T1005
T1027
T1027.013
T1036.005
T1105
T1107
T1112
T1189
T1204
T1505.003
T1543.003
T1555.003
T1560.001
T1566.002
T1567.002
T1569.002
T1574.001
T1574.002
T1583.004
T1583.006
T1584.004
T1594
T1486
T1070
T1070.003
T1070.004
T1070.005
T1070.006
T1070.007
T1070.008
T1071.001
T1071.003

Software / Tooling

Cobalt Strike
Joomla
Backdoor.Oldrea
Heyoka Backdoor
White Company
ClickFix

Campaigns & Victims

TAG‑112 routinely leverages popular CMS platforms—most notably Joomla—to create footholds in low‑visibility web environments. Their operations often start with a simple script injection that masquerades as a legitimate site update, followed by the delivery of Cobalt Strike for lateral movement and data theft. The actor’s capability to manipulate captive portal traffic and generate doppelganger domains expands its reach into corporate networks via MS Azure OAuth/device code phishing campaigns. Notable past operations include the Storm‑2945 sub‑cluster associated with Midnight Blizzard, which employed DNS hijacking on captive portals and distributed malware through seemingly benign downloads. While TAG‑112’s public-facing tactics focus on web exploitation, the underlying toolset suggests a willingness to shift into more aggressive ransomware or data‐exfiltration activities when financial incentives align. Their operational tempo appears periodic—periods of heightened activity coincide with major regional events affecting Tibetan communities—indicating a politically motivated component underpinning their broader opportunistic agenda.

IOC Patterns

  • Malicious JavaScript injection into website content
  • Spoofed TLS certificate error page prompting download of fake security certificate
  • Deployment of a Cobalt Strike payload via disguised download
  • File and folder deletion, self‑deletion trace removal
  • Domain names mimicking legitimate Microsoft services
  • DNS and HTTP traffic manipulation from captive portal networks
  • Malicious Android application package distribution
  • Phishing URLs targeting OAuth/device code flows

Recommended Actions

  • Patch Joomla installations promptly to close identified vulnerabilities
  • Monitor websites for unauthorized script injections and anomalous download prompts
  • Implement web filtering/WAF rules to detect and block known Cobalt Strike signatures
  • Validate SSL/TLS certificates and educate users about certificate errors
  • Deploy endpoint detection to monitor for file deletions and cleanup activity
  • Implement integrity monitoring and file change alerts
  • Block or sandbox known backdoor binaries associated with TAG‑112
  • Detect anomalous DNS/HTTP redirects on captive portal networks
  • Validate legitimacy of domain names used in authentication flows
  • Apply MFA and conditional access for device registration in Microsoft Entra ID
  • Secure captive portal infrastructure with intrusion prevention systems

Suggested Tags

Chinese state-sponsored actor
Tibetan organizations targeting
CMS vulnerability exploitation
Web-based delivery vector
Cobalt Strike usage
TAG‑112
Agrius
Advanced Persistent Threat 39
Chafer
Cadelspy
Remexi
ITG07
phishing
doppelganger-domain
captiveportal
dns-hijack
traffic-manipulation
adversary-in-the-middle
device-code-phishing
oauth-phishing
malware-delivery
android-apk

Confidence Assessment

The available data reflects a consistent pattern of Joomla exploitation, certificate spoofing, and Cobalt Strike deployment attributed to TAG‑112. Multiple independent reports corroborate these techniques, providing moderate to high confidence in the actor’s core capabilities. However, gaps remain regarding the full extent of their operational tempo, financial motives, and persistence mechanisms beyond the disclosed incidents. Further intelligence on post‑exploitation behaviors and potential ransomware pivoting would enhance assessment accuracy.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-1 Hash 1 SHA-256 Hash 2 Filename 5 Domain 7 IPv4 Address 5

References

  1. attack.mitre.org — Cited by web research for: Advanced Persistent Threat 39
  2. attack.mitre.org — Cited by web research for: APT34
  3. www.microsoft.com — Cited by web research for: the SVR
  4. www.recordedfuture.com — Cited by web research for: T1574.002
  5. cloud.google.com — Cited by web research for: T1594
  6. https://attack.mitre.org/techniques/T1005/ — Cited by AI analysis.
  7. https://malpedia.caad.fkie.fraunhofer.de/actor/tag-112 — Cited by AI analysis.

Intel Summary

34

Techniques

45

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Critical Infrastructure
Chinese state-sponsored actor
Tibetan organizations targeting
CMS vulnerability exploitation
Web-based delivery vector
Cobalt Strike usage
TAG‑112
Agrius
Advanced Persistent Threat 39
Chafer
Cadelspy
Remexi
ITG07
phishing
doppelganger-domain
captiveportal
dns-hijack
traffic-manipulation
adversary-in-the-middle
device-code-phishing
oauth-phishing
malware-delivery
android-apk

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.