Russian Hackers Launch Sophisticated Attack on Tajikistan Government Using Weaponized Word Documents


# Russian Hackers Target Tajikistan with New Phishing Tactics

Russian-aligned threat actor TAG-110 has launched a sophisticated spear-phishing campaign against Tajikistan, marking a significant shift in their attack methodology. Instead of their previously documented HATVIBE loader, the group is now utilizing macro-enabled Word templates as initial payloads, according to Recorded Future’s Insikt Group.

“This campaign is likely targeting government, educational, and research institutions within Tajikistan,” researchers noted. “These cyber espionage operations likely aim to gather intelligence for influencing regional politics or security, particularly during sensitive events.”

TAG-110, also known as UAC-0063, has been active since at least 2021 and shares similarities with the Russian state-sponsored APT28 group. The threat actor has historically targeted European embassies and organizations across Central Asia, East Asia, and Europe.

The new campaign, detected in January 2025, represents a tactical evolution. Instead of using HTA-embedded attachments to deliver HATVIBE malware, the attackers now employ macro-enabled Word template (.DOTM) files. These templates contain VBA macros that:

– Place the document template in Microsoft Word’s startup folder for persistence
– Establish communication with command-and-control servers
– Execute additional VBA code delivered through C2 responses

While researchers couldn’t confirm the exact nature of second-stage payloads, they believe successful infections likely lead to deployment of known TAG-110 tools such as HATVIBE, CHERRYSPY, LOGPIE, or potentially new custom espionage malware.

The phishing emails use Tajikistan government-themed documents as lures, consistent with the group’s established pattern of weaponizing legitimate government documents.

Share This Article