TAG-124
0 incidentes
0 paises
0 sectores
apt Ultimo: -
Aliases: LandUpdate808
TAG-124 is a prolific and technically sophisticated malicious traffic distribution system (TDS) that first emerged in early 2024. It operates by leveraging a multi-layered infrastructure, including thousands of compromised WordPress websites and actor-controlled servers, to deliver diverse malware payloads. Unique in its operational model, TAG-124 functions as a service for a wide array of other cybercriminal and state-sponsored threat actors, including prominent ransomware groups like Rhysida and Interlock, and the state-linked TA866 (Asylum Ambuscade). This specialized role in the initial infection chain, coupled with its advanced evasion tactics, sets it apart as a foundational component in the broader cybercriminal ecosystem. While the exact individuals or group behind TAG-124 remain anonymous, it is also known by the aliases LandUpdate808, KongTuke, and Chaya_002.
Sectores objetivo (SOCRadar)
Energy & Utilities Information ServicesEducational ServicesHealthCare & Social Assistance