Also known as: LandUpdate808, tracked as, Bluenoroff, cryptocurrency businesses, ATMs, Andariel, Hidden Cobra, Diamond Sleet, defense, IT organizations, Jade Sleet, cryptocurrency companies, Emerald Sleet, Kimsuky, Tech Sectors, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Sapphire Sleet, Citrine Sleet, Onyx Sleet, ZINC, UNC4899, THALLIUM, Agrius, APT34
TAG-124 has evolved into a multi‑phase threat group that leverages compromised WordPress content management systems as a front for lateral deployment of malware. Through SEO poisoning and JavaScript injection the actor delivers deceptive Google Chrome update pages, which trigger PowerShell download cradles that in turn drop signed kernel drivers exploiting CVE‑2025‑61155 (UpdateCheckerX64.sys). In addition to ransomware delivery, TAG-124 facilitates finance‑oriented malware families such as SocGholish and D3F@ck Loader via a click‑to‑run campaign known as MintLoader or MintsLoader. The actor’s modular toolkit includes the use of legitimate utilities (PowerShell, PsExec, javaw.exe) and backdoor frameworks like ScreenConnect, while maintaining persistence by installing Windows services through MSI installers. The malware also manipulates the Windows registry to register services, uses JavaScript executed via legitimate binaries to evade detection, and exfiltrates documents (.doc, .pdf, .hwp) along with recently accessed file paths discovered through .lnk parsing. A hallmark of TAG‑124’s tactics is ClickFix— a clipboard‑based prompt that forces execution of arbitrary commands through disguised UI dialogs. The actor routinely refines its infrastructure by rotating IP addresses and domains (e.g., TEMP.Hermit, GenKryptik.HHER) and using traffic distribution servers to anonymize command-and-control activity. TAG-124 is closely linked with larger ransomware groups like Rhysida and Interlock; the group has also distributed other ransomware families such as Kimsuky-related payloads, reflecting a strategy of “big‑game hunting” across critical sectors worldwide.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TAG-124 operates a sophisticated traffic‑distribution system that compromises WordPress sites, injects malicious JavaScript and serves fake Chrome update pages to deliver malware, including ransomware such as Interlock. The actor targets high‑profile sectors—government, finance, healthcare, critical infrastructure, and defense—across more than twenty countries and frequently updates its infrastructure for persistence and evasion.
Goals & Targeting
The primary objective of TAG‑124 appears to be monetization through high‑value extortion: acquiring access to protected data, exfiltrating it for blackmail and leveraging ransomware to maximize financial extraction. The actor selects targets based on sectoral value—government agencies, finance, healthcare, utilities, and defense—where downtime or data possession yields significant leverage. Geographically the group focuses on countries with strategic importance to its alleged backers, including China, North Korea, Iran, United States, India, Japan, UAE, Russia, Ukraine, Belgium, Saudi Arabia and other nations critical to geopolitical interests. By using widely available web exploitation channels (WordPress sites) and sophisticated delivery mechanisms (fake browser updates), TAG‑124 can reach a broad audience while maintaining low risk of detection. Strategically, the attacker prioritizes assets that hold both high operational value and public visibility; successful compromises are then amplified through media coverage to increase bargaining power or propaganda value. The blend of ransomware distribution with data exfiltration positions the group as a dual‑use threat capable of both immediate financial gain and long‑term intelligence gathering.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TAG‑124’s operations are characterized by a rapid deployment model, often launching new campaigns within days of discovering unpatched WordPress sites. The group distributes malicious payloads through both drive‑by infection and phishing via compromised websites that mimic legitimate update prompts. Victim profiles skew toward high‑profile or resource‑rich organizations—government bodies, financial institutions, healthcare providers, and critical infrastructure operators—that can command sizable ransom payments. Operational tempo is aggressive: the actor continuously renews its traffic‑distribution server lists, rotates file hashes (e.g., UpdateCheckerX64.sys), and changes distribution domains to maintain persistence. Historical incidents link TAG‑124 not only to domestic ransomware outbreaks but also to distributed extortion campaigns that leveraged multiple malware families simultaneously. Notable past operations include compromises of the Polish Centre for Testing and Certification, ECOWAS, and several high‑profile WordPress sites serving deceptive update pages. The actor demonstrates a modular approach: individual components (e.g., MintLoader click‑to‑run, SocGholish payloads, Interlock ransomware) are reusable across campaigns, suggesting an ecosystem of dropper modules that can be mixed to adapt to different targets and defensive postures.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the compiled profile of TAG‑124 is moderate. The evidence aggregates from multiple source feeds and known malware families provides reasonable assurance of the actor’s methods, capabilities, tools, and target selection; however, gaps remain regarding precise attribution, full scope of financial motives, detailed operational timelines, and potential undisclosed affiliates. Future intelligence gathering should focus on corroborating infrastructure details (IP/DNS rotation patterns) and refining associations with larger ransomware collaborations.
No campaigns linked yet.
No observed data linked yet.
26
Techniques
46
Tools
0
Campaigns
138
IOCs
0
Observed Data
9
Tactics