PK

TAG-140TAG-140

Also known as: TAG-140

Origin
PK
Known aliases
1

Profile

TAG-140 is a threat actor group that primarily targets Indian government entities, employing cyber espionage tactics such as phishing and malware campaigns. They have deployed a new variant of the DRAT RAT, known as DRAT V2, which utilizes a ClickFix lure and executes a remote script via mshta.exe to establish persistence and facilitate data exfiltration. Their operations include the use of the BroaderAspect loader and a custom TCP-based C2 protocol, enabling a range of post-exploitation activities. TAG-140's activities reflect a pattern of iterative advancement in their malware arsenal and delivery techniques, complicating detection and attribution efforts.

Aliases· 1

TAG-140

References

  1. https://www.recordedfuture.com/research/drat-v2-updated-drat-emerges-tag-140s-arsenal

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
TAG-28
Actor
TA402
Actor
GrayBravo
Actor
TAG-56
Actor
RAZOR TIGER
Actor
Storm-2077
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.