TAG-140
0 incidentes
0 paises
0 sectores
apt PK Ultimo: -
TAG-140 is a cyber espionage threat actor group that has been active since at least 2019, exhibiting a consistent pattern of refining its malware arsenal and delivery techniques. It is assessed with moderate confidence to be a suspected Pakistani state-aligned group. The group operates as a sub-cluster or operational affiliate of the broader Transparent Tribe collective, also tracked as APT36, SideCopy, ProjectM, and MYTHIC Leopard. TAG-140's primary motivation is cyber espionage and information theft, focusing on harvesting sensitive data from its targets. A distinguishing characteristic of TAG-140 is its rapid evolution in tradecraft and its employment of an interchangeable suite of Remote Access Trojans to complicate detection and attribution efforts. Recent activities notably involve the use of ClickFix-style social engineering lures, specifically spoofing the Indian Ministry of Defence to ensnare victims.