Russia-Linked Cyber Spies Unleash “Hatvibe” Havoc Across Europe and Asia
Russia-linked TAG-110 uses custom malware HATVIBE and CHERRYSPY to target Europe and Asia. These malicious tools are the cyber equivalent of a Swiss army knife, minus the corkscrew, aimed at government entities, human rights groups, and educational institutions. It’s a digital circus act, with espionage as the main event!

Hot Take:
Looks like Russia’s TAG-110 has been busy pulling a James Bond act, sneaking into virtual boardrooms across Asia and Europe. Instead of a tuxedo and gadgets from Q, they opted for a digital toolkit of custom malware. But hey, who needs a license to kill when you’ve got a license to chill… in other people’s servers?
Key Points:
- TAG-110, a Russia-linked threat actor, targets organizations in Central Asia, East Asia, and Europe.
- They use custom malware tools, HATVIBE and CHERRYSPY, for cyber-espionage.
- HATVIBE acts as a loader, delivering CHERRYSPY for data exfiltration.
- Campaigns align with Russian geopolitical interests, focusing on post-Soviet states.
- Researchers provide Indicators of Compromise and security rules for detection.
Already a member? Log in here
