The group TAG-110, linked to the Russian intelligence entity APT28, infiltrated IT systems of government and academic institutions in the Central Asian country.

Insikt Group, a cybersecurity research unit of Recorded Future, published a report on May 22, 2025, detailing a Russian cyberespionage operation targeting Tajikistan. The group TAG-110, directly connected to APT28—a Russian military intelligence entity also known as “BlueDelta”—is believed to have carried out the attack in January and February 2025.

The hackers infiltrated IT systems of government, university, and research institutions in Tajikistan by sending phishing emails containing fake documents related to government or national security topics. Once access was gained, they installed espionage tools such as Cherryspie, Logpie, and other customized malware.

According to Insikt Group, TAG-110 has been conducting cyber operations in Central Asia since 2021 and has also targeted organizations in India, Israel, Mongolia, and Ukraine.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.