CN

TAG-112TAG-112

Also known as: TAG-112

Origin
CN
Known aliases
1

Profile

TAG-112 is a Chinese state-sponsored APT that compromised Tibetan websites, including Tibet Post and Gyudmed Tantric University, to deliver Cobalt Strike malware. The group exploited vulnerabilities in the Joomla CMS to embed malicious JavaScript that spoofed a TLS certificate error, tricking users into downloading a compromised security certificate. TAG-112's infrastructure, concealed using Cloudflare, shows notable overlap with TAG-102, but it employs less sophisticated tactics, relying on Cobalt Strike rather than custom malware. The campaign reflects ongoing cyber-espionage efforts targeting Tibetan entities, likely for information collection and surveillance.

Aliases· 1

TAG-112

References

  1. https://www.recordedfuture.com/research/china-nexus-tag-112-compromises-tibetan-websites

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
APT12
Actor
TAG-28
Actor
APT21
Actor
GTG-1002
Actor
TAG-124
Actor
APT-C-12
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.