Russian hackers have been linked to a cyberespionagetargeting organizations in Central Asia, East Asia, and Europe through the HATVIBE and CHERRYSPY malware.

Recorded Future's Insikt Group has named the group TAG-110 and noted that it shares similarities with a threat group monitored by Ukraine's CERT-UA as UAC-0063. This, in turn, shares similarities with the APT28 group.
“ Using the custom malware HATVIBE and CHERRYSPY, Russian hackers TAG-110 primarily attack government entities, human rights groups, and educational institutions ,” the cybersecurity firm said in a report. “ HATVIBE acts as a loader for the deployment of CHERRYSPY, which is a Python backdoor used for data extraction and espionage .”
See also: New version of NodeStealer malware targets Facebook Ads Manager accounts
The use of HATVIBE and CHERRYSPY malware by the TAG-110 group was first reported by CERT-UA in late May 2023. At that time, the malware was used in a cyberattack on government agencies in Ukraine. About a year later, it was also used in a hack of an anonymous scientific research institution in the country.
Since then, 62 unique victims have been identified in eleven countries, with notable incidents in Tajikistan, Kyrgyzstan, Kazakhstan, Turkmenistan, and Uzbekistan. This indicates that Central Asia is the primary target region.
Smaller numbers of victims have also been identified in Armenia, China, Hungary, India, Greece and Ukraine.
Russian hackers exploit vulnerabilities in web applications (e.g. Rejetto HTTP File Server) and send phishing emails to gain initial access and install the HATVIBE and CHERRYSPY malware.
See also: LodaRAT malware: Targets Windows users and steals credentials
“TAG-110’s efforts are likely part of a broader Russian strategy to gather intelligence on geopolitical developments and maintain influence in post-Soviet states,” Recorded Future reported. “These areas are important to Moscow due to strained relations following the Russian invasion of Ukraine.”

“These covert activities align with Russia’s broader hybrid warfare , aimed at destabilizing NATO countries, weakening their military capabilities, and pressuring political alliances,” Recorded Future said, describing the efforts as “calculated and persistent.”
Russian hackers have become a significant force in cyberspace, using their skills for both criminal and political purposes. As technology continues to advance, it is likely that these hackers will continue to adapt and evolve their tactics for more effective attacks. This means that they will continue to pose a significant challenge to governments and organizations.
See also: Emmenhtal Loader uses scripts to spread Lumma and other Malware
The warnings and efforts to combat Russian hacking highlight the need for international cooperation and innovation in the ever-changing cybersecurity. It is therefore important for both individuals and organizations to remain vigilant and continually update their security measures to protect themselves from potential attacks. With increased awareness and cooperation, we can work to mitigate the impact of Russian hackers on global cybersecurity.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
