Uptime Hamster: 10d 12h 57mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza TAG-124

TAG-124

0 incidentes 0 paises 0 sectores apt Ultimo: -
Aliases: LandUpdate808
Ver en IntelTracker → APTTrail →
TAG-124 is a prolific and technically sophisticated malicious traffic distribution system (TDS) that first emerged in early 2024. It operates by leveraging a multi-layered infrastructure, including thousands of compromised WordPress websites and actor-controlled servers, to deliver diverse malware payloads. Unique in its operational model, TAG-124 functions as a service for a wide array of other cybercriminal and state-sponsored threat actors, including prominent ransomware groups like Rhysida and Interlock, and the state-linked TA866 (Asylum Ambuscade). This specialized role in the initial infection chain, coupled with its advanced evasion tactics, sets it apart as a foundational component in the broader cybercriminal ecosystem. While the exact individuals or group behind TAG-124 remain anonymous, it is also known by the aliases LandUpdate808, KongTuke, and Chaya_002.

Aliases del actor

LandUpdate808

Actores similares

tag-22actor · 1Local Data Stagingactor · 1Contagious Interviewapt · 1TAG-100apt · 0TAG-28apt · 0TAG-140apt · 0MUT-1244apt · 0TAG-112apt · 0TAG-38apt · 0TAG-56apt · 0
Tecnicas MITRE
T1102.002 - Bidirectional Communication, T1140 - Deobfuscate/Decode Files or Information, T1204.002 - Malicious File, T1071.001 - Web Protocols, T1583.001 - Domains, T1059.001 - PowerShell
Tipo
apt
Pais origen
-
Motivacion
-
Impacto
57
Actualizado
Sat, 17 Ma

Sectores objetivo (SOCRadar)

Energy & Utilities Information ServicesEducational ServicesHealthCare & Social Assistance