Russia-Linked TAG-110 Swaps HTA for Macro Mayhem in Tajikistan Cyberattack Fiasco
TAG-110, a Russia-aligned threat actor, targets Tajikistan’s government and education sectors with macro-enabled Word templates, a departure from their usual HATVIBE malware. This spear-phishing campaign aims to gather intelligence for regional influence, especially during sensitive political events.

Hot Take:
Just when you thought it was safe to open a Word document, TAG-110 swoops in with some retro flair, proving that even in the world of cyber espionage, vintage is always in vogue. Move over, HATVIBE, because macro-enabled Word templates are back in style, and they’re causing quite the stir in Tajikistan’s digital fashion scene!
Key Points:
- TAG-110 shifts tactics, using macro-enabled Word templates instead of the previously used HATVIBE loader.
- The campaign targets government, educational, and research institutions in Tajikistan.
- The spear-phishing emails leverage Tajikistan government-themed documents as bait.
- TAG-110 is associated with Russian nation-state hacking group APT28.
- The group’s activities have been previously documented in Central Asia, East Asia, and Europe.
Already a member? Log in here