Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TAG-124

Also known as: LandUpdate808, tracked as, Bluenoroff, cryptocurrency businesses, ATMs, Andariel, Hidden Cobra, Diamond Sleet, defense, IT organizations, Jade Sleet, cryptocurrency companies, Emerald Sleet, Kimsuky, Tech Sectors, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Sapphire Sleet, Citrine Sleet, Onyx Sleet, ZINC, UNC4899, THALLIUM, Agrius, APT34

Description

TAG-124 has evolved into a multi‑phase threat group that leverages compromised WordPress content management systems as a front for lateral deployment of malware. Through SEO poisoning and JavaScript injection the actor delivers deceptive Google Chrome update pages, which trigger PowerShell download cradles that in turn drop signed kernel drivers exploiting CVE‑2025‑61155 (UpdateCheckerX64.sys). In addition to ransomware delivery, TAG-124 facilitates finance‑oriented malware families such as SocGholish and D3F@ck Loader via a click‑to‑run campaign known as MintLoader or MintsLoader. The actor’s modular toolkit includes the use of legitimate utilities (PowerShell, PsExec, javaw.exe) and backdoor frameworks like ScreenConnect, while maintaining persistence by installing Windows services through MSI installers. The malware also manipulates the Windows registry to register services, uses JavaScript executed via legitimate binaries to evade detection, and exfiltrates documents (.doc, .pdf, .hwp) along with recently accessed file paths discovered through .lnk parsing. A hallmark of TAG‑124’s tactics is ClickFix— a clipboard‑based prompt that forces execution of arbitrary commands through disguised UI dialogs. The actor routinely refines its infrastructure by rotating IP addresses and domains (e.g., TEMP.Hermit, GenKryptik.HHER) and using traffic distribution servers to anonymize command-and-control activity. TAG-124 is closely linked with larger ransomware groups like Rhysida and Interlock; the group has also distributed other ransomware families such as Kimsuky-related payloads, reflecting a strategy of “big‑game hunting” across critical sectors worldwide.

Goals & Targeting

Targeted Sectors

Government
Financial services
Healthcare
Defense
Education
Telecommunications
Transportation
Critical infrastructure
Energy
Non profit
Retail
Media
Aviation
Maritime
Hospitality
Gaming

Targeted Countries / Regions

CN
KP
IR
US
IN
JP
AE
GB
MX
RU
BY
UA
TW

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

TAG-124 operates a sophisticated traffic‑distribution system that compromises WordPress sites, injects malicious JavaScript and serves fake Chrome update pages to deliver malware, including ransomware such as Interlock. The actor targets high‑profile sectors—government, finance, healthcare, critical infrastructure, and defense—across more than twenty countries and frequently updates its infrastructure for persistence and evasion.

Goals & Targeting

The primary objective of TAG‑124 appears to be monetization through high‑value extortion: acquiring access to protected data, exfiltrating it for blackmail and leveraging ransomware to maximize financial extraction. The actor selects targets based on sectoral value—government agencies, finance, healthcare, utilities, and defense—where downtime or data possession yields significant leverage. Geographically the group focuses on countries with strategic importance to its alleged backers, including China, North Korea, Iran, United States, India, Japan, UAE, Russia, Ukraine, Belgium, Saudi Arabia and other nations critical to geopolitical interests. By using widely available web exploitation channels (WordPress sites) and sophisticated delivery mechanisms (fake browser updates), TAG‑124 can reach a broad audience while maintaining low risk of detection. Strategically, the attacker prioritizes assets that hold both high operational value and public visibility; successful compromises are then amplified through media coverage to increase bargaining power or propaganda value. The blend of ransomware distribution with data exfiltration positions the group as a dual‑use threat capable of both immediate financial gain and long‑term intelligence gathering.

Enhanced Description

Key Capabilities

  • Traffic distribution for malware dissemination
  • Injection of malicious JavaScript on compromised WordPress sites
  • SEO poisoning of legitimate websites
  • Display of deceptive Google Chrome update prompts
  • ClickFix technique to trigger arbitrary command execution
  • PowerShell‑based download cradle for ransomware and NodeSnakeRAT
  • Dropping signed kernel driver exploiting CVE‑2025‑61155 (UpdateCheckerX64.sys)
  • Executing JavaScript via legal javaw.exe binary
  • Installing services through MSI installers such as ScreenConnect and registering them as Windows services
  • Collecting victim documents (Office, PDF, HWP) and recently accessed paths via .lnk parsing
  • Leveraging click‑to‑run campaigns MintLoader/MintsLoader for initial access

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion

ATT&CK Techniques

T1047
T1033
T1543
T1587.001
T1204.002
T1608.004
T1053
T1005
T1190
T1583.001
T1021
T1016
T1059
T1021.001
T1562.004
T1204.004
T1059.001
T1059.007
T1543.003
T1105

Software / Tooling

KongTuke
SocGholish
D3F@ck Loader
NodeSnakeRAT
Interlock ransomware
Hotta Killer
ScreenConnect
MintLoader
MintsLoader
UpdateAgent
ComeBacker
Global
ClickFix
PoolRAT
PondRAT
OdicLoader
CollectionRAT
Gleaming Pisces
GenKryptik
Trojan
Infostealer
Havoc
LODEINFO
PsExec
Wevtutil
Turla
Cobalt
PowerShell
Dark

Campaigns & Victims

TAG‑124’s operations are characterized by a rapid deployment model, often launching new campaigns within days of discovering unpatched WordPress sites. The group distributes malicious payloads through both drive‑by infection and phishing via compromised websites that mimic legitimate update prompts. Victim profiles skew toward high‑profile or resource‑rich organizations—government bodies, financial institutions, healthcare providers, and critical infrastructure operators—that can command sizable ransom payments. Operational tempo is aggressive: the actor continuously renews its traffic‑distribution server lists, rotates file hashes (e.g., UpdateCheckerX64.sys), and changes distribution domains to maintain persistence. Historical incidents link TAG‑124 not only to domestic ransomware outbreaks but also to distributed extortion campaigns that leveraged multiple malware families simultaneously. Notable past operations include compromises of the Polish Centre for Testing and Certification, ECOWAS, and several high‑profile WordPress sites serving deceptive update pages. The actor demonstrates a modular approach: individual components (e.g., MintLoader click‑to‑run, SocGholish payloads, Interlock ransomware) are reusable across campaigns, suggesting an ecosystem of dropper modules that can be mixed to adapt to different targets and defensive postures.

IOC Patterns

  • Malicious JavaScript injection in WordPress sites
  • Fake Chrome browser update landing pages
  • Clipboard‑based ClickFix prompt for arbitrary command execution
  • Compromised domain names used for malicious landing pages
  • Malicious IP addresses (e.g., 64.94.85.248, 45.61.136.67)
  • Signed kernel driver drop with renamed filename UpdateCheckerX64.sys
  • Execution of JavaScript via javaw.exe binary
  • Suspicious MSI installer registration of services like ScreenConnect
  • SHA‑1 hash of malicious driver (7556AE58C215B8245A43F764F0676C7A8F0FDD1A)
  • Epoch-timed parameter in URL access (138.199.156.22:8080)
  • Malicious file types: jar.jar, polers.dll, move.dll, rundll32.exe
  • Misspelled query parameters such as "refferer"

Recommended Actions

  • Implement web‑filtering and detection of malicious JavaScript in HTTP traffic
  • Block known compromised WordPress sites and monitor website integrity for unauthorized changes
  • Patch and secure all WordPress installations promptly to remove exploitation vectors
  • Educate users on deceptive browser update prompts and safe browsing practices
  • Integrate threat intelligence feeds to detect indicators of TAG‑124 activity
  • Monitor and alert on suspicious PowerShell execution that downloads external payloads
  • Block or quarantine unknown kernel driver installations such as UpdateCheckerX64.sys
  • Apply timely patches for CVE‑2025‑61155 vulnerability across affected Windows systems
  • Restrict traffic to known malicious IP addresses (e.g., 138.199.156.22)
  • Enforce application whitelisting for Java executables like javaw.exe to prevent illicit script execution
  • Audit and monitor the registration of new services from MSI installers, ensuring only approved software is installed

Suggested Tags

TAG-124
Traffic Distribution System
WordPress Compromise
Malicious JavaScript Injection
Fake Browser Update
ClickFix Exploit
Ransomware Distribution
SocGholish
D3F@ck Loader
PowerShell Delivery
Kernel Driver Deployment
Interlock Ransomware
MintLoader Campaign
ScreenConnect Service Registration
Data Exfiltration
CVE-2025-61155
JavaScript Abuse
Fake Chrome Update
Click‑to‑Run

Confidence Assessment

The confidence in the compiled profile of TAG‑124 is moderate. The evidence aggregates from multiple source feeds and known malware families provides reasonable assurance of the actor’s methods, capabilities, tools, and target selection; however, gaps remain regarding precise attribution, full scope of financial motives, detailed operational timelines, and potential undisclosed affiliates. Future intelligence gathering should focus on corroborating infrastructure details (IP/DNS rotation patterns) and refining associations with larger ransomware collaborations.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. unit42.paloaltonetworks.com — Cited by web research for: Bluenoroff
  2. attack.mitre.org — Cited by web research for: Tech Sectors
  3. www.fortinet.com — Cited by web research for: T1059
  4. www.recordedfuture.com — Cited by web research for: T1583.001
  5. www.recordedfuture.com — Cited by web research for: Financial Services

Intel Summary

26

Techniques

46

Tools

0

Campaigns

138

IOCs

0

Observed Data

9

Tactics

Tags

Ransomware
Critical Infrastructure
Phishing
Malware Distribution
Region-Specific (Poland, West Africa)
TAG-124
Traffic Distribution System
WordPress Compromise
Malicious JavaScript Injection
Fake Browser Update
ClickFix Exploit
Ransomware Distribution
SocGholish
D3F@ck Loader
PowerShell Delivery
Kernel Driver Deployment
Interlock Ransomware
MintLoader Campaign
ScreenConnect Service Registration
Data Exfiltration
CVE-2025-61155
JavaScript Abuse
Fake Chrome Update
Click‑to‑Run

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.