Cyber Threat Report: 'Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage Campaign'

Report Author Recorded Future
Publication Date 2024-02-17
Original Reporting Source
Attributed to Nation Belarus, Russia
Related Intrusion Sets UAC-0114 , TA473 , Winter Vivern , TAG-70
Identified CVEs CVE-2022-27926 , CVE-2023-5631
Victim Sectors Defense, Transportation, National Government, Education

The Insikt Group has observed the TAG-70 using cross-site scripting (XSS) vulnerabilities to target Roundcube webmail servers in Europe. The group's focus is on government, military, and national infrastructure-related entities. The observed activities overlap with those reported by other security vendors under aliases of Winter Vivern, TA473, and UAC0114. The group likely serves the interests of Belarus and Russia and has been active since at least December 2020, with primary targets in European and Central Asian governments. In their most recent campaign, TAG-70 began exploiting Roundcube webmail servers around October 2023. At least 80 organizations were targeted, primarily in Georgia, Poland, and Ukraine. This campaign is linked to TAG70's activity against Uzbekistan government mail servers, previously reported by Insikt Group in February 2023.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques

ATT&CK ID Title Associated Tactics
T1078 Valid Accounts Defense Evasion, Initial Access, Persistence, Privilege Escalation
T1571 Non-Standard Port Command and Control
T1083 File and Directory Discovery Discovery
T1056 Input Capture Collection, Credential Access
T1114 Email Collection Collection
T1203 Exploitation for Client Execution Execution
T1212 Exploitation for Credential Access Credential Access
T1566 Phishing Initial Access