Also known as: tag propagation, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Chanitor, Agrius, Threat Intelligence, Chimaera, APT34, the SVR
TAG‑112 primarily conducts campaigns against Tibetan organizations by leveraging well‑known weaknesses in Joomla installations. Once an attacker compromises a site, they inject malicious JavaScript that displays a spoofed TLS certificate error. This trick forces users to download a fake security certificate which then installs a Cobalt Strike beacon for remote control. In addition to web delivery, the actor uses Cloudflare for infrastructure obfuscation and employs ad‑versary‑in‑the‑middle tactics on captive portals to redirect DNS and HTTP flows through controlled domains. Their malware bundles include self‑deleting components that erase file and command histories, clear registry entries, and remove network share connections—exemplifying a layered defense‑evasion approach. TAG‑112’s toolkit also contains backdoors such as Backdoor.Oldrea, Heyoka Backdoor, and White Company, which provide persistence and facilitate credential harvesting, especially from web browsers. The presence of AI‑augmented operational support suggests an evolving threat capability aimed at streamlining both attack vectors and post‑exploitation stages. While the group’s financial motives are noted in its description, most evidence points toward espionage objectives—gaining political intelligence on Tibetan communities—while maintaining a low‑profile footprint that complicates attribution.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TAG‑112 is a Chinese state‑sponsored Advanced Persistent Threat that has exploited Joomla CMS vulnerabilities on Tibetan community websites to drop Cobalt Strike and steal data while evading detection. The group blends low‑tech social engineering techniques—such as spoofed TLS certificate prompts—with more sophisticated traffic manipulation on captive portals and phishing of Microsoft Entra ID device registration flows. Its operations demonstrate a mix of espionage and opportunistic financial motives, targeting both governmental and civilian entities.
Goals & Targeting
The strategic objective of TAG‑112 is dual: acquire politically relevant information from Tibetan community organizations and exploit any discovered vulnerabilities for further infiltration. By targeting sites with CMS weaknesses, the actor ensures continuous footholds in critical regions while simultaneously using advanced ransomware‑style tactics when financially motivated. Their global reach—spanning China, Ukraine, Russia, Iran, and the U.S.—indicates a broadening threat envelope beyond Tibetan entities. Their targeting profile prefers publicly accessible web properties to initiate attacks but also extends to corporate Microsoft environments through phishing of OAuth/device code flows. Such diversification serves both espionage of sensitive data and opportunistic financial gains via potential ransomware or data exfiltration, reflecting a flexible operational paradigm.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TAG‑112 routinely leverages popular CMS platforms—most notably Joomla—to create footholds in low‑visibility web environments. Their operations often start with a simple script injection that masquerades as a legitimate site update, followed by the delivery of Cobalt Strike for lateral movement and data theft. The actor’s capability to manipulate captive portal traffic and generate doppelganger domains expands its reach into corporate networks via MS Azure OAuth/device code phishing campaigns. Notable past operations include the Storm‑2945 sub‑cluster associated with Midnight Blizzard, which employed DNS hijacking on captive portals and distributed malware through seemingly benign downloads. While TAG‑112’s public-facing tactics focus on web exploitation, the underlying toolset suggests a willingness to shift into more aggressive ransomware or data‐exfiltration activities when financial incentives align. Their operational tempo appears periodic—periods of heightened activity coincide with major regional events affecting Tibetan communities—indicating a politically motivated component underpinning their broader opportunistic agenda.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data reflects a consistent pattern of Joomla exploitation, certificate spoofing, and Cobalt Strike deployment attributed to TAG‑112. Multiple independent reports corroborate these techniques, providing moderate to high confidence in the actor’s core capabilities. However, gaps remain regarding the full extent of their operational tempo, financial motives, and persistence mechanisms beyond the disclosed incidents. Further intelligence on post‑exploitation behaviors and potential ransomware pivoting would enhance assessment accuracy.
No campaigns linked yet.
No observed data linked yet.
34
Techniques
45
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics